
CVE-2026-40227 In systemd 260 before 261, a local unprivileged user can trigger an assert via an IPC API call with an array or map that has a null element. https://www.cve.org/CVERecord?id=CVE-2026-40227
Post summary
A local unprivileged user can trigger an assert in systemd 260 by calling an IPC API with a null element, potentially causing a crash. No PoC, exploit code, patch, or exploitation data is reported.
