{"id":"SUSE-SU-2026:0991-1","summary":"Security update for systemd","details":"This update for systemd fixes the following issue:\n\n- CVE-2026-4105: privilege escalation due to improper access control in RegisterMachine D-Bus method (bsc#1259650).\n- udev: check for invalid chars in various fields received from the kernel (bsc#1259697).  \n\nChangelog:\n\n cbf8ee66ee machined: reject invalid class types when registering machines\n 1a55ad48da udev: fix review mixup\n 1eba76668c udev-builtin-net-id: print cescaped bad attributes\n cbd4b55380 udev: ensure tag parsing stays within bounds\n 5973d3b1cc udev: ensure there is space for trailing NUL before calling sprintf\n f038eb6c8b udev: check for invalid chars in various fields received from the kernel\n","modified":"2026-03-25T08:30:52.472722Z","published":"2026-03-24T07:23:00Z","related":["CVE-2026-4105"],"upstream":["CVE-2026-4105"],"references":[{"type":"ADVISORY","url":"https://www.suse.com/support/update/announcement/2026/suse-su-20260991-1/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1259650"},{"type":"REPORT","url":"https://bugzilla.suse.com/1259697"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-4105"}],"affected":[{"package":{"name":"systemd","ecosystem":"SUSE:Linux Enterprise Server 12 SP5-LTSS","purl":"pkg:rpm/suse/systemd&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP5-LTSS"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"228-157.75.1"}]}],"ecosystem_specific":{"binaries":[{"libsystemd0-32bit":"228-157.75.1","libsystemd0":"228-157.75.1","libudev1":"228-157.75.1","systemd-bash-completion":"228-157.75.1","systemd-devel":"228-157.75.1","systemd-sysvinit":"228-157.75.1","systemd":"228-157.75.1","udev":"228-157.75.1","libudev-devel":"228-157.75.1","libudev1-32bit":"228-157.75.1","systemd-32bit":"228-157.75.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:0991-1.json"}},{"package":{"name":"systemd","ecosystem":"SUSE:Linux Enterprise Server LTSS Extended Security 12 SP5","purl":"pkg:rpm/suse/systemd&distro=SUSE%20Linux%20Enterprise%20Server%20LTSS%20Extended%20Security%2012%20SP5"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"228-157.75.1"}]}],"ecosystem_specific":{"binaries":[{"libsystemd0":"228-157.75.1","libudev1-32bit":"228-157.75.1","systemd-32bit":"228-157.75.1","systemd-bash-completion":"228-157.75.1","systemd":"228-157.75.1","udev":"228-157.75.1","libsystemd0-32bit":"228-157.75.1","libudev-devel":"228-157.75.1","libudev1":"228-157.75.1","systemd-devel":"228-157.75.1","systemd-sysvinit":"228-157.75.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:0991-1.json"}}],"schema_version":"1.7.5"}