CVE-2026-15060

NameCVE-2026-15060
DescriptionWhen systemd-machined >= v259 (or v258 with a custom `polkit` policy that allows `register-machine` access) is running on a desktop system, an unprivileged user logged in a desktop graphical session can kill arbitrary processes, even privileged ones. - versions older than v259 are not affected, unless unprivileged access is granted for the `register-machine` polkit action via a local, custom policy config file - versions older than v258 are not affected - unrelated to the systemd service manager (pid 1 or user session managers) - systemd-machined is not typically installed by default, and is typically in an optional, separate package (e.g.: systemd-container) - terminal-only or remote sessions (e.g.: ssh) are not affected
SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
systemd (PTS)bullseye247.3-7+deb11u5fixed
bullseye (security)247.3-7+deb11u8fixed
bookworm252.39-1~deb12u2fixed
bookworm (security)252.38-1~deb12u1fixed
trixie257.13-1~deb13u1fixed
forky, sid261.2-1fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
systemdsourcebullseye(not affected)
systemdsourcebookworm(not affected)
systemdsourcetrixie(not affected)
systemdsource(unstable)261.2-1

Notes

[trixie] - systemd <not-affected> (Vulnerable code not present)
[bookworm] - systemd <not-affected> (Vulnerable code not present)
[bullseye] - systemd <not-affected> (Vulnerable code not present)
https://github.com/systemd/systemd/security/advisories/GHSA-qwv4-3gwc-w5g8
Fixed by: https://github.com/systemd/systemd/commit/8eb162df81b4f684c9d444e458dbf22674f964fb (v261.2)

Search for package or bug name: Reporting problems