🛡️ SUSE-SU-2026:20822-1 — systemd (CVE-2026-4105 +1 more)
Description
Security update for systemd
This update for systemd fixes the following issues:
Security issues:
- CVE-2026-4105: privilege escalation due to improper access control in RegisterMachine D-Bus method (bsc#1259650).
- CVE-2026-29111: local unprivileged user can trigger an assert in systemd (bsc#1259418).
- udev: check for invalid chars in various fields received from the kernel (bsc#1259697).
Non security issues:
- Name libsystemd-{shared,core} based on the major version of systemd and the
package release number (bsc#1228081, bsc#1256427)
- detect-virt: bare-metal GCE only for x86 and i386 (bsc#1254293)
Changelog:
- a943e3ce2f machined: reject invalid class types when registering machines
- 71593f77db udev: fix review mixup
- 73a89810b4 udev-builtin-net-id: print cescaped bad attributes
- 0f360bfdc0 udev-builtin-net_id: do not assume the current interface name is ethX
- 40905232e2 udev: ensure tag parsing stays within bounds
- 7bce9026e3 udev: ensure there is space for trailing NUL before calling sprintf
- d018ac1ea3 udev: check for invalid chars in various fields received from the kernel
- aef6e11921 core/cgroup: avoid one unnecessary strjoina()
- cc7426f38a sd-json: fix off-by-one issue when updating parent for array elements
- 26a748f727 core: validate input cgroup path more prudently
- 99d8308fde core/dbus-manager: propagate meaningful dbus errors from EnqueueMarkedJobs
- 8bbac1d508 detect-virt: bare-metal GCE only for x86 and i386
Affected software
SUSE-SU-2026:20822-1 is recorded against 1 package.
- systemd (fixed in 254.27-3.1)
Timeline and source
Published on 24 March 2026 and last revised on 26 March 2026. No public exploit is currently recorded for this entry. Record sourced from OSV.
References
www.suse.com (Advisory)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
www.suse.com (Web)
www.suse.com (Web)
Details
Affected Packages
| Software | From version | Fixed in |
|---|---|---|
| systemd | — | 254.27-3.1 |
References
Similar Threats
- Unknown ALSA-2026:19068
- Unknown ALSA-2026:19213
- Unknown ALSA-2026:13677
- Unknown ALSA-2025:22660
- Unknown AZL-64289
Free Vulnerability Check
Is your site affected by SUSE-SU-2026:20822-1?
BotEraser helps you identify potentially vulnerable plugins and themes by checking your installation against SUSE-SU-2026:20822-1 and other known CVE records.
Scan My Site Free →No credit card required · Results in minutes
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the vulnerabilities listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.