There are 3 open security issues in trixie.
3 issues left for the package maintainer to handle:
- CVE-2026-15059:
(needs triaging)
Local unprivileged users can terminate arbitrary local processes via a systemd-oomd IPC API due to a missing path traversal validation.
- CVE-2026-16742:
(needs triaging)
systemd-homed contains a local privilege escalation bug via arbitrary system group addition to a local, logged in, homed-managed user
- CVE-2026-40228:
(needs triaging)
In systemd 259, systemd-journald can send ANSI escape sequences to the terminals of arbitrary users when a "logger -p emerg" command is executed, if ForwardToWall=yes is set.
You can find information about how to handle these issues in the security team's documentation.