Executive brief
systemd is a system and service manager used in Linux distributions to manage system processes and services. A flaw in the systemd-machined service allows a local unprivileged user to register a malicious machine object via the D-Bus interface, bypassing access controls and gaining the ability to execute arbitrary commands with root privileges on the host system.
Technical details
The vulnerability is an improper access control flaw in the systemd-machined service's RegisterMachine D-Bus method, caused by insufficient validation of the class parameter. A local unprivileged user can exploit this by providing a crafted class value when registering a machine, resulting in a usable attacker-controlled machine object being left in place. By invoking methods on this privileged object, the attacker can execute arbitrary commands with root privileges. The attack requires local access and does not require authentication beyond standard D-Bus access, allowing privilege escalation from unprivileged to root.
Affected products
- systemd systemd
Timeline
- 2026-03-13: disclosed