DEBIAN-CVE-2026-4105

Source
https://security-tracker.debian.org/tracker/CVE-2026-4105
Import Source
https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2026-4105.json
JSON Data
https://api.osv.dev/v1/vulns/DEBIAN-CVE-2026-4105
Upstream
Published
2026-03-13T19:55:13Z
Modified
2026-09-14T17:03:10Z
Severity
  • 6.7 (Medium) CVSS_V3 - CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H CVSS Calculator
Summary
[none]
Details

A flaw was found in systemd. The systemd-machined service contains an Improper Access Control vulnerability due to insufficient validation of the class parameter in the RegisterMachine D-Bus (Desktop Bus) method. A local unprivileged user can exploit this by attempting to register a machine with a specific class value, which may leave behind a usable, attacker-controlled machine object. This allows the attacker to invoke methods on the privileged object, leading to the execution of arbitrary commands with root privileges on the host system.

References

Affected packages

Debian:12 / systemd

Package

Name
systemd
Purl
pkg:deb/debian/systemd?arch=source&distro=bookworm

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
252.39-1~deb12u2

Affected versions

252.*
252.6-1
252.6-1+loong64
252.11-1~deb12u1
252.11-1
252.12-1~deb12u1
252.14-1~deb12u1
252.16-1~deb12u1
252.17-1~deb12u1
252.18-1~deb12u1
252.19-1~deb12u1
252.20-1~deb12u1
252.21-1~deb12u1
252.22-1~deb12u1
252.23-1~deb12u1
252.24-1~deb12u1
252.25-1~deb12u1
252.26-1~deb12u1
252.26-1~deb12u2~bpo11+1
252.26-1~deb12u2
252.27-1~deb12u1
252.28-1~deb12u1
252.29-1~deb12u1~bpo11+1
252.29-1~deb12u1
252.30-1~deb12u1
252.30-1~deb12u2
252.31-1~deb12u1
252.32-1~deb12u1
252.33-1~deb12u1
252.36-1~deb12u1
252.38-1~deb12u1
252.39-1~deb12u1

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Database specific

source
"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2026-4105.json"

Debian:13 / systemd

Package

Name
systemd
Purl
pkg:deb/debian/systemd?arch=source&distro=trixie

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
257.13-1~deb13u1

Affected versions

257.*
257.7-1
257.8-1~deb13u1
257.8-1~deb13u2
257.9-1~deb13u1

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Database specific

source
"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2026-4105.json"

Debian:14 / systemd

Package

Name
systemd
Purl
pkg:deb/debian/systemd?arch=source&distro=forky

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
260~rc3-1

Affected versions

257.*
257.7-1
257.8-1~deb13u1
257.8-1~deb13u2
257.9-1~deb13u1
257.13-1~deb13u1
Other
258~rc1-1
258~rc2-1
258~rc2-2
258~rc3-1
258~rc4-1
258-1
259~rc1-1
259~rc2-1
259~rc3-1
259-1
260~rc1-1
260~rc1-2
260~rc2-1
258.*
258.1-1
258.1-2
259.*
259.1-1

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Database specific

source
"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2026-4105.json"