SUSE Systemd Vulnerability Leads to Local Privilege Escalation Risk

SUSE Systemd Vulnerability Leads to Local Privilege Escalation Risk

First seen 9 Sep 2026, 18:45 UTC Linuxsecurity 45.9

Article Content

Browse articles
ThreatCluster

A security update for systemd addresses CVE-2026-16742, a local privilege escalation vulnerability affecting SUSE and openSUSE systems. This flaw arises from missing record signature verification in `systemd-homed`, allowing unauthorized users to escalate privileges. The vulnerability has a CVSS score of 6.7, indicating a moderate severity. Alongside this, two other CVEs, CVE-2026-29111 and CVE-2026-40226, were also mentioned in the updates, with scores of 6.8 and 7.1 respectively. The updates were released on September 3, 2026, and users are urged to apply the patches promptly to mitigate risks. The affected systems include various versions of SUSE and openSUSE, particularly those utilizing systemd. The updates also address non-security issues related to `systemd-resolved`. Current status indicates that the vulnerabilities are patched, but awareness and action are crucial for system administrators.

Key Points: • CVE-2026-16742 poses a local privilege escalation risk in systemd. • SUSE and openSUSE systems are affected; patches were released on September 3, 2026. • The vulnerability has a CVSS score of 6.7, indicating moderate severity.

Ask AI about this cluster

Timeline

2026-03-23
CVE-2026-29111 published
CVE-2026-29111 disclosed, affecting systemd with a CVSS score of 6.8.
Linuxsecurity
2026-04-10
CVE-2026-40226 published
CVE-2026-40226 disclosed, with a CVSS score of 7.1, affecting systemd.
Linuxsecurity
2026-08-10
CVE-2026-16742 published
CVE-2026-16742 disclosed, leading to local privilege escalation in systemd.
Linuxsecurity
2026-09-03
SUSE releases patches for systemd vulnerabilities
SUSE released updates addressing CVE-2026-16742 and related issues, urging users to patch.
Linuxsecurity