Bug 2444375 - systemd: local user privilege escalation (GHSA-6pwp-j5vg-5j6m)
Summary: systemd: local user privilege escalation (GHSA-6pwp-j5vg-5j6m)
Keywords:
Status: CLOSED ERRATA
Alias: None
Product: Fedora
Classification: Fedora
Component: systemd
Version: 44
Hardware: Unspecified
OS: Linux
unspecified
medium
Target Milestone: ---
Assignee: systemd-maint
QA Contact: Fedora Extras Quality Assurance
URL:
Whiteboard:
Depends On:
Blocks: BetaFreezeException, F44BetaFreezeException
TreeView+ depends on / blocked
 
Reported: 2026-03-04 13:49 UTC by Zbigniew Jędrzejewski-Szmek
Modified: 2026-03-11 00:16 UTC (History)
8 users (show)

Fixed In Version: systemd-259.3-1.fc44
Clone Of:
Environment:
Last Closed: 2026-03-11 00:16:19 UTC
Type: ---
Embargoed:


Attachments (Terms of Use)

Description Zbigniew Jędrzejewski-Szmek 2026-03-04 13:49:47 UTC
See https://github.com/systemd/systemd/security/advisories/GHSA-6pwp-j5vg-5j6m.

> When systemd-machined >= v259 is running on a desktop system, an unprivileged user logged in a desktop graphical session can escalate to root via an IPC call.

This is fixed in v259.2. I'm filing this for the purposes of a freeze exception.

Reproducible: Always

Comment 1 Zbigniew Jędrzejewski-Szmek 2026-03-04 13:52:54 UTC
systemd-machined is in systemd-container.rpm. It is in the @virtualization-headless comps group.

Comment 2 Fedora Blocker Bugs Application 2026-03-04 13:54:04 UTC
Proposed as a Freeze Exception for 44-beta by Fedora user zbyszek using the blocker tracking app because:

 Fixes a security vulnerability.

Comment 3 Fedora Update System 2026-03-04 16:04:06 UTC
FEDORA-2026-c1c45c4b2d (systemd-259.3-1.fc44) has been submitted as an update to Fedora 44.
https://bodhi.fedoraproject.org/updates/FEDORA-2026-c1c45c4b2d

Comment 4 Fedora Update System 2026-03-05 01:44:21 UTC
FEDORA-2026-c1c45c4b2d has been pushed to the Fedora 44 testing repository.
Soon you'll be able to install the update with the following command:
`sudo dnf upgrade --enablerepo=updates-testing --refresh --advisory=FEDORA-2026-c1c45c4b2d`
You can provide feedback for this update here: https://bodhi.fedoraproject.org/updates/FEDORA-2026-c1c45c4b2d

See also https://fedoraproject.org/wiki/QA:Updates_Testing for more information on how to test updates.

Comment 5 Fedora Update System 2026-03-11 00:16:19 UTC
FEDORA-2026-c1c45c4b2d (systemd-259.3-1.fc44) has been pushed to the Fedora 44 stable repository.
If problem still persists, please make note of it in this bug report.


Note You need to log in before you can comment on or make changes to this bug.