Critical systemd Vulnerabilities Affect Multiple Ubuntu Releases

Critical systemd Vulnerabilities Affect Multiple Ubuntu Releases

First seen 8 Jun 2026, 21:23 UTC Ubuntulaunchpad.netLinuxsecurity 92% similarity 72.0

Article Content

Browse articles
ThreatCluster

Two significant vulnerabilities in systemd have been reported, affecting Ubuntu 22.04 LTS, 24.04 LTS, and 25.10. The first, CVE-2026-40226, allows local attackers to escape to the host system and execute arbitrary code via improper handling of configuration files in systemd-nspawn. The second, CVE-2023-7008, involves incorrect validation of DNSSEC records by systemd-resolved, enabling DNS record manipulation. Both vulnerabilities necessitate immediate system updates and reboots to mitigate risks. Ubuntu Pro users benefit from extended security coverage for these issues. The vulnerabilities were disclosed in a security notice on June 8, 2026.

Key Points: • CVE-2026-40226 allows local code execution via systemd-nspawn vulnerabilities. • CVE-2023-7008 affects DNSSEC validation in systemd-resolved, impacting Ubuntu 22.04 LTS. • Immediate updates and reboots are required to mitigate these vulnerabilities.

ThreatCluster AI

Timeline

2023-12-23
CVE-2023-7008 published
CVE-2023-7008 was published, detailing DNSSEC validation issues in systemd-resolved.
Ubuntu
2026-04-10
CVE-2026-40226 published
CVE-2026-40226 was published, highlighting vulnerabilities in systemd-nspawn allowing local code execution.
Ubuntu
2026-06-08
Security notice issued for systemd vulnerabilities
Ubuntu released USN-8402-1, detailing critical vulnerabilities in systemd affecting multiple releases.
Ubuntu

Community

Browse all →