Nixpkgs security tracker

Login with GitHub

Details of issue NIXPKGS-2026-1041

NIXPKGS-2026-1041
published on
Permalink CVE-2026-40225
6.4 MEDIUM
  • CVSS version: 3.1
  • Attack vector (AV): PHYSICAL
  • Attack complexity (AC): HIGH
  • Privileges required (PR): NONE
  • User interaction (UI): NONE
  • Scope (S): UNCHANGED
  • Confidentiality impact (C): HIGH
  • Integrity impact (I): HIGH
  • Availability impact (A): HIGH
updated 2 weeks, 4 days ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse ignored
    2 packages
    • udev
    • rofi-systemd
  • @LeSuisse restored package udev
  • @LeSuisse ignored
    43 packages
    • tests.pkg-config.defaultPkgConfigPackages.libsystemd
    • tests.pkg-config.defaultPkgConfigPackages.libudev
    • vscode-extensions.coolbear.systemd-unit-file
    • gnomeExtensions.systemd-offline-update-indicator
    • python313Packages.jupyterhub-systemdspawner
    • python313Packages.systemdunitparser
    • systemd-lsp
    • haskellPackages.libsystemd-journal
    • python312Packages.systemdunitparser
    • python313Packages.systemd-python
    • python314Packages.jupyterhub-systemdspawner
    • ocamlPackages_latest.systemd
    • update-systemd-resolved
    • python312Packages.jupyterhub-systemdspawner
    • gnomeExtensions.systemd-status
    • python314Packages.systemdunitparser
    • python314Packages.systemd-python
    • python312Packages.systemd-python
    • ocamlPackages.systemd
    • php84Extensions.systemd
    • php85Extensions.systemd
    • php82Extensions.systemd
    • gnomeExtensions.systemd-manager
    • prometheus-systemd-exporter
    • systemd
    • systemdgenie
    • systemdLibs
    • haskellPackages.warp-systemd
    • systemd-credsubst
    • systemd-journal2gelf
    • systemd-lock-handler
    • phpExtensions.systemd
    • haskellPackages.systemd
    • systemd-manager-tui
    • php83Extensions.systemd
    • systemd-bootchart
    • systemdMinimal
    • systemd-netlogd
    • systemd-wait
    • systemd-language-server
    • haskellPackages.systemd-api
    • nagiosPlugins.check_systemd
    • systemdUkify
  • @LeSuisse accepted
  • @LeSuisse published on GitHub
In udev in systemd before 260, local root execution can …

In udev in systemd before 260, local root execution can occur via malicious hardware devices and unsanitized kernel output.

Affected products

systemd
  • <260

Matching in nixpkgs

pkgs.udev

System and service manager for Linux

Ignored packages (44)

pkgs.systemd

System and service manager for Linux

pkgs.systemd-netlogd

Forwards messages from the journal to other hosts over the network

pkgs.systemd-bootchart

Boot performance graphing tool from systemd

  • nixos-unstable 235
    • nixpkgs-unstable 235
    • nixos-unstable-small 235
  • nixos-25.11 235
    • nixos-25.11-small 235
    • nixpkgs-25.11-darwin 235

pkgs.ocamlPackages.systemd

OCaml module for native access to the systemd facilities

  • nixos-unstable 1.3
    • nixpkgs-unstable 1.3
    • nixos-unstable-small 1.3
  • nixos-25.11 1.3
    • nixos-25.11-small 1.3
    • nixpkgs-25.11-darwin 1.3

pkgs.update-systemd-resolved

Helper script for OpenVPN to directly update the DNS settings of a link through systemd-resolved via DBus

pkgs.python313Packages.systemdunitparser

SystemdUnitParser is an extension to Python's configparser.RawConfigParser to properly parse systemd unit files

  • nixos-unstable 0.4
    • nixpkgs-unstable 0.4
    • nixos-unstable-small 0.4
  • nixos-25.11 0.4
    • nixos-25.11-small 0.4
    • nixpkgs-25.11-darwin 0.4

Package maintainers