{
  "threat_severity" : "Moderate",
  "public_date" : "2026-03-23T21:03:56Z",
  "bugzilla" : {
    "description" : "systemd: systemd: Arbitrary code execution or Denial of Service via spurious IPC API call data",
    "id" : "2450505",
    "url" : "https://bugzilla.redhat.com/show_bug.cgi?id=2450505"
  },
  "cvss3" : {
    "cvss3_base_score" : "7.8",
    "cvss3_scoring_vector" : "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
    "status" : "verified"
  },
  "cwe" : "CWE-1287",
  "details" : [ "systemd, a system and service manager, (as PID 1) hits an assert and freezes execution when an unprivileged IPC API call is made with spurious data. On version v249 and older the effect is not an assert, but stack overwriting, with the attacker controlled content. From version v250 and newer this is not possible as the safety check causes an assert instead. This IPC call was added in v239, so versions older than that are not affected. Versions 260-rc1, 259.2, 258.5, and 257.11 contain patches. No known workarounds are available.", "A flaw was found in systemd, a system and service manager. An unprivileged user can exploit this vulnerability by making an Inter-Process Communication (IPC) API call with spurious data. In older versions (v249 and earlier), this can lead to stack overwriting with attacker-controlled content, potentially enabling arbitrary code execution or privilege escalation. In newer versions (v250 and later), the flaw causes systemd to assert and freeze, resulting in a Denial of Service (DoS)." ],
  "affected_release" : [ {
    "product_name" : "Red Hat Enterprise Linux 10",
    "release_date" : "2026-05-05T00:00:00Z",
    "advisory" : "RHSA-2026:13651",
    "cpe" : "cpe:/o:redhat:enterprise_linux:10.1",
    "package" : "systemd-0:257-13.el10_1.3"
  }, {
    "product_name" : "Red Hat Enterprise Linux 10",
    "release_date" : "2026-05-19T00:00:00Z",
    "advisory" : "RHSA-2026:19068",
    "cpe" : "cpe:/o:redhat:enterprise_linux:10.2",
    "package" : "systemd-0:257-23.el10_2.1"
  }, {
    "product_name" : "Red Hat Enterprise Linux 9",
    "release_date" : "2026-05-05T00:00:00Z",
    "advisory" : "RHSA-2026:13677",
    "cpe" : "cpe:/a:redhat:enterprise_linux:9",
    "package" : "systemd-0:252-55.el9_7.9"
  }, {
    "product_name" : "Red Hat Enterprise Linux 9",
    "release_date" : "2026-05-19T00:00:00Z",
    "advisory" : "RHSA-2026:19213",
    "cpe" : "cpe:/a:redhat:enterprise_linux:9",
    "package" : "systemd-0:252-67.el9_8.2"
  }, {
    "product_name" : "Red Hat Enterprise Linux 9",
    "release_date" : "2026-05-05T00:00:00Z",
    "advisory" : "RHSA-2026:13677",
    "cpe" : "cpe:/o:redhat:enterprise_linux:9",
    "package" : "systemd-0:252-55.el9_7.9"
  }, {
    "product_name" : "Red Hat Enterprise Linux 9",
    "release_date" : "2026-05-19T00:00:00Z",
    "advisory" : "RHSA-2026:19213",
    "cpe" : "cpe:/o:redhat:enterprise_linux:9",
    "package" : "systemd-0:252-67.el9_8.2"
  }, {
    "product_name" : "Red Hat Hardened Images",
    "release_date" : "2026-04-09T00:00:00Z",
    "advisory" : "RHSA-2026:7299",
    "cpe" : "cpe:/a:redhat:hummingbird:1",
    "package" : "systemd-main-260.1-2.1.hum1"
  }, {
    "product_name" : "Red Hat OpenShift distributed tracing 3.9.3",
    "release_date" : "2026-05-06T00:00:00Z",
    "advisory" : "RHSA-2026:14162",
    "cpe" : "cpe:/a:redhat:openshift_distributed_tracing:3.9::el9",
    "package" : "rhosdt/opentelemetry-collector-rhel9:1778056267"
  }, {
    "product_name" : "Red Hat OpenShift distributed tracing 3.9.3",
    "release_date" : "2026-05-06T00:00:00Z",
    "advisory" : "RHSA-2026:14162",
    "cpe" : "cpe:/a:redhat:openshift_distributed_tracing:3.9::el9",
    "package" : "rhosdt/opentelemetry-rhel9-operator:1778056233"
  }, {
    "product_name" : "Red Hat OpenShift distributed tracing 3.9.3",
    "release_date" : "2026-05-06T00:00:00Z",
    "advisory" : "RHSA-2026:14162",
    "cpe" : "cpe:/a:redhat:openshift_distributed_tracing:3.9::el9",
    "package" : "rhosdt/opentelemetry-target-allocator-rhel9:1778056245"
  } ],
  "package_state" : [ {
    "product_name" : "Red Hat Enterprise Linux 10",
    "fix_state" : "Will not fix",
    "package_name" : "NetworkManager",
    "cpe" : "cpe:/o:redhat:enterprise_linux:10"
  }, {
    "product_name" : "Red Hat Enterprise Linux 10",
    "fix_state" : "Affected",
    "package_name" : "rpm-ostree",
    "cpe" : "cpe:/o:redhat:enterprise_linux:10"
  }, {
    "product_name" : "Red Hat Enterprise Linux 7",
    "fix_state" : "Affected",
    "package_name" : "systemd",
    "cpe" : "cpe:/o:redhat:enterprise_linux:7"
  }, {
    "product_name" : "Red Hat Enterprise Linux 8",
    "fix_state" : "Will not fix",
    "package_name" : "NetworkManager",
    "cpe" : "cpe:/o:redhat:enterprise_linux:8"
  }, {
    "product_name" : "Red Hat Enterprise Linux 8",
    "fix_state" : "Affected",
    "package_name" : "systemd",
    "cpe" : "cpe:/o:redhat:enterprise_linux:8"
  }, {
    "product_name" : "Red Hat Enterprise Linux 9",
    "fix_state" : "Will not fix",
    "package_name" : "NetworkManager",
    "cpe" : "cpe:/o:redhat:enterprise_linux:9"
  }, {
    "product_name" : "Red Hat OpenShift Container Platform 4",
    "fix_state" : "Affected",
    "package_name" : "NetworkManager",
    "cpe" : "cpe:/a:redhat:openshift:4"
  }, {
    "product_name" : "Red Hat OpenShift Container Platform 4",
    "fix_state" : "Affected",
    "package_name" : "rhcos",
    "cpe" : "cpe:/a:redhat:openshift:4"
  }, {
    "product_name" : "Red Hat OpenShift Container Platform 4",
    "fix_state" : "Affected",
    "package_name" : "systemd",
    "cpe" : "cpe:/a:redhat:openshift:4"
  } ],
  "references" : [ "https://www.cve.org/CVERecord?id=CVE-2026-29111\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-29111\nhttps://github.com/systemd/systemd/commit/1d22f706bd04f45f8422e17fbde3f56ece17758a\nhttps://github.com/systemd/systemd/commit/20021e7686426052e3a7505425d7e12085feb2a6\nhttps://github.com/systemd/systemd/commit/21167006574d6b83813c7596759b474f56562412\nhttps://github.com/systemd/systemd/commit/3cee294fe8cf4fa0eff933ab21416d099942cabd\nhttps://github.com/systemd/systemd/commit/42aee39107fbdd7db1ccd402a2151822b2805e9f\nhttps://github.com/systemd/systemd/commit/54588d2dedff54bfb6036670820650e4ea74628f\nhttps://github.com/systemd/systemd/commit/7ac3220213690e8a8d6d2a6e81e43bd1dce01d69\nhttps://github.com/systemd/systemd/commit/80acea4ef80a4bb78560ed970c34952299b890d6\nhttps://github.com/systemd/systemd/commit/b5fd14693057e5f2c9b4a49603be64ec3608ff6c\nhttps://github.com/systemd/systemd/commit/efa6ba2ab625aaa160ac435a09e6482fc63bdbe8\nhttps://github.com/systemd/systemd/security/advisories/GHSA-gx6q-6f99-m764" ],
  "name" : "CVE-2026-29111",
  "mitigation" : {
    "value" : "Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.",
    "lang" : "en:us"
  },
  "csaw" : false
}