CVE-2026-40226 Details
Description
In nspawn in systemd 233 through 259 before 260, an escape-to-host action can occur via a crafted optional config file.
A vulnerability in systemd nspawn versions 233 through 259 prior to 260 allows for an escape-to-host action through a crafted optional configuration file. This issue arises from two parsing bugs that affect the 'PivotRoot=', 'BindUser=', and 'Ephemeral=' options. When exploited, the container is spawned on the host's root filesystem instead of the container image, with elevated privileges.
Users can update to systemd version 260, 259.4, 258.6, or 257.12, all of which include the necessary patches. Alternatively, as a temporary measure, users can sanitize storage directories to prevent the use of '.nspawn' configuration files or ensure that such files do not include the 'PivotRoot=', 'BindUser=', or 'Ephemeral=' options.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Apr 14, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/systemd/systemd/security/advisories/GHSA-9mj4-rrc3-gjcx | [email protected] | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-348 | Use of Less Trusted Source | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| systemd project systemd | >= 233, < 257.12 >= 258, < 258.6 >= 259, < 259.4 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Apr 17, 2026 | Initial Analysis | [email protected] |
| Apr 10, 2026 | New CVE Received | [email protected] |