CVE-2026-40228 Details
Description
In systemd 259, systemd-journald can send ANSI escape sequences to the terminals of arbitrary users when a "logger -p emerg" command is executed, if ForwardToWall=yes is set.
A vulnerability exists in systemd version 259, specifically within the systemd-journald component. When the 'ForwardToWall' option is enabled, systemd-journald can transmit ANSI escape sequences to the terminals of arbitrary users. This occurs when an 'emerg' priority log message is sent using the 'logger' command. The vulnerability takes advantage of the default logging behavior in certain Linux distributions, including Ubuntu 26.04 pre-release and Arch Linux, where 'ForwardToWall' is set to 'yes'. This flaw can potentially be exploited to execute arbitrary code as root by manipulating terminal emulator vulnerabilities, particularly in XTerm.
Users can disable the 'ForwardToWall' option in systemd-journald's configuration file or add 'systemd.journald.forward_to_wall=no' to their kernel command line.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Apr 10, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| http://www.openwall.com/lists/oss-security/2026/05/05/1 | CVE | |
| https://www.openwall.com/lists/oss-security/2026/04/08/1 | [email protected] | ExploitMailing ListThird Party Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-669 | Incorrect Resource Transfer Between Spheres | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| systemd project systemd | 259 - |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| May 5, 2026 | CVE Modified | CVE |
| Apr 17, 2026 | Initial Analysis | [email protected] |
| Apr 10, 2026 | New CVE Received | [email protected] |