Systemd · Systemd · CVE-2026-29111
**Name of the Vulnerable Software and Affected Versions**
systemd versions prior to 260-rc1
systemd versions prior to 259.2
systemd versions prior to 258.5
systemd versions prior to 257.11
systemd versions 239 through 249
**Description**
systemd, a system and service manager, can freeze execution or experience stack overwriting when an unprivileged Inter-Process Communication (IPC) API call is made with invalid data. Versions prior to v239 are not affected. Versions v249 and earlier are susceptible to stack overwriting, allowing an attacker to control content. From version v250 onwards, the issue triggers an assert, preventing stack overwriting. The vulnerable IPC call was introduced in version v239.
**Recommendations**
Update to systemd version 260-rc1 or later.
Update to systemd version 259.2 or later.
Update to systemd version 258.5 or later.
Update to systemd version 257.11 or later.