{
  "document": {
    "aggregate_severity": {
      "text": "Important"
    },
    "category": "csaf_security_advisory",
    "csaf_version": "2.0",
    "distribution": {
      "text": "TuxCare License Agreement",
      "tlp": {
        "label": "WHITE",
        "url": "https://www.first.org/tlp/"
      }
    },
    "lang": "en",
    "notes": [
      {
        "category": "legal_disclaimer",
        "text": "This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content, or a modified version of it, you must provide attribution to Cloud Linux Inc. and provide a link to the original.",
        "title": "Terms of Use"
      },
      {
        "category": "details",
        "text": "CVE-2026-29111: validate the control group path in the\n  GetUnitByControlGroup D-Bus method, rejecting non-absolute or\n  non-normalized input to prevent stack exhaustion from an oversized,\n  attacker-controlled string\n- Skip the test-fs-util symlink touch_file check when the build kernel\n  does not support chmod() on a symlink (-EOPNOTSUPP), so the build's\n  test phase no longer aborts during the package build",
        "title": "Details"
      }
    ],
    "publisher": {
      "category": "vendor",
      "contact_details": "https://tuxcare.com/contact/",
      "name": "TuxCare",
      "namespace": "https://tuxcare.com/"
    },
    "references": [
      {
        "category": "self",
        "summary": "https://cve.tuxcare.com/els/releases/CLSA-2026:1784813417",
        "url": "https://cve.tuxcare.com/els/releases/CLSA-2026:1784813417"
      },
      {
        "category": "self",
        "summary": "Canonical URL",
        "url": "https://security.tuxcare.com/csaf/v2/els_os/centos-stream8els/advisories/2026/clsa-2026_1784813417.json"
      }
    ],
    "tracking": {
      "current_release_date": "2026-07-23T13:32:13Z",
      "generator": {
        "date": "2026-07-23T13:32:13Z",
        "engine": {
          "name": "pyCSAF"
        }
      },
      "id": "CLSA-2026:1784813417",
      "initial_release_date": "2026-07-23T13:32:13Z",
      "revision_history": [
        {
          "date": "2026-07-23T13:32:13Z",
          "number": "1",
          "summary": "Initial version"
        }
      ],
      "status": "final",
      "version": "1"
    },
    "title": "systemd: Fix of CVE-2026-29111"
  },
  "product_tree": {
    "branches": [
      {
        "branches": [
          {
            "branches": [
              {
                "category": "product_name",
                "name": "Community Enterprise Operating System 8",
                "product": {
                  "name": "Community Enterprise Operating System 8",
                  "product_id": "CentOS-Stream-8",
                  "product_identification_helper": {
                    "cpe": "cpe:2.3:o:centos:centos:8:*:*:*:*:*:*:*"
                  }
                }
              }
            ],
            "category": "product_family",
            "name": "Community Enterprise Operating System"
          }
        ],
        "category": "vendor",
        "name": "Red Hat, Inc."
      },
      {
        "branches": [
          {
            "branches": [
              {
                "category": "product_version",
                "name": "systemd-pam-0:239-82.el8.1.tuxcare.els1.x86_64",
                "product": {
                  "name": "systemd-pam-0:239-82.el8.1.tuxcare.els1.x86_64",
                  "product_id": "systemd-pam-0:239-82.el8.1.tuxcare.els1.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/tuxcare/systemd-pam@239-82.el8.1.tuxcare.els1?arch=x86_64"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "systemd-libs-0:239-82.el8.1.tuxcare.els1.x86_64",
                "product": {
                  "name": "systemd-libs-0:239-82.el8.1.tuxcare.els1.x86_64",
                  "product_id": "systemd-libs-0:239-82.el8.1.tuxcare.els1.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/tuxcare/systemd-libs@239-82.el8.1.tuxcare.els1?arch=x86_64"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "systemd-container-0:239-82.el8.1.tuxcare.els1.x86_64",
                "product": {
                  "name": "systemd-container-0:239-82.el8.1.tuxcare.els1.x86_64",
                  "product_id": "systemd-container-0:239-82.el8.1.tuxcare.els1.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/tuxcare/systemd-container@239-82.el8.1.tuxcare.els1?arch=x86_64"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "systemd-journal-remote-0:239-82.el8.1.tuxcare.els1.x86_64",
                "product": {
                  "name": "systemd-journal-remote-0:239-82.el8.1.tuxcare.els1.x86_64",
                  "product_id": "systemd-journal-remote-0:239-82.el8.1.tuxcare.els1.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/tuxcare/systemd-journal-remote@239-82.el8.1.tuxcare.els1?arch=x86_64"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "systemd-0:239-82.el8.1.tuxcare.els1.x86_64",
                "product": {
                  "name": "systemd-0:239-82.el8.1.tuxcare.els1.x86_64",
                  "product_id": "systemd-0:239-82.el8.1.tuxcare.els1.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/tuxcare/systemd@239-82.el8.1.tuxcare.els1?arch=x86_64"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "systemd-devel-0:239-82.el8.1.tuxcare.els1.x86_64",
                "product": {
                  "name": "systemd-devel-0:239-82.el8.1.tuxcare.els1.x86_64",
                  "product_id": "systemd-devel-0:239-82.el8.1.tuxcare.els1.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/tuxcare/systemd-devel@239-82.el8.1.tuxcare.els1?arch=x86_64"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "systemd-udev-0:239-82.el8.1.tuxcare.els1.x86_64",
                "product": {
                  "name": "systemd-udev-0:239-82.el8.1.tuxcare.els1.x86_64",
                  "product_id": "systemd-udev-0:239-82.el8.1.tuxcare.els1.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/tuxcare/systemd-udev@239-82.el8.1.tuxcare.els1?arch=x86_64"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "systemd-tests-0:239-82.el8.1.tuxcare.els1.x86_64",
                "product": {
                  "name": "systemd-tests-0:239-82.el8.1.tuxcare.els1.x86_64",
                  "product_id": "systemd-tests-0:239-82.el8.1.tuxcare.els1.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/tuxcare/systemd-tests@239-82.el8.1.tuxcare.els1?arch=x86_64"
                  }
                }
              }
            ],
            "category": "architecture",
            "name": "x86_64"
          },
          {
            "branches": [
              {
                "category": "product_version",
                "name": "systemd-libs-0:239-82.el8.1.tuxcare.els1.i686",
                "product": {
                  "name": "systemd-libs-0:239-82.el8.1.tuxcare.els1.i686",
                  "product_id": "systemd-libs-0:239-82.el8.1.tuxcare.els1.i686",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/tuxcare/systemd-libs@239-82.el8.1.tuxcare.els1?arch=i686"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "systemd-container-0:239-82.el8.1.tuxcare.els1.i686",
                "product": {
                  "name": "systemd-container-0:239-82.el8.1.tuxcare.els1.i686",
                  "product_id": "systemd-container-0:239-82.el8.1.tuxcare.els1.i686",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/tuxcare/systemd-container@239-82.el8.1.tuxcare.els1?arch=i686"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "systemd-0:239-82.el8.1.tuxcare.els1.i686",
                "product": {
                  "name": "systemd-0:239-82.el8.1.tuxcare.els1.i686",
                  "product_id": "systemd-0:239-82.el8.1.tuxcare.els1.i686",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/tuxcare/systemd@239-82.el8.1.tuxcare.els1?arch=i686"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "systemd-devel-0:239-82.el8.1.tuxcare.els1.i686",
                "product": {
                  "name": "systemd-devel-0:239-82.el8.1.tuxcare.els1.i686",
                  "product_id": "systemd-devel-0:239-82.el8.1.tuxcare.els1.i686",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/tuxcare/systemd-devel@239-82.el8.1.tuxcare.els1?arch=i686"
                  }
                }
              }
            ],
            "category": "architecture",
            "name": "i686"
          }
        ],
        "category": "vendor",
        "name": "TuxCare"
      }
    ],
    "relationships": [
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "systemd-pam-0:239-82.el8.1.tuxcare.els1.x86_64 as a component of Community Enterprise Operating System 8",
          "product_id": "CentOS-Stream-8:systemd-pam-0:239-82.el8.1.tuxcare.els1.x86_64"
        },
        "product_reference": "systemd-pam-0:239-82.el8.1.tuxcare.els1.x86_64",
        "relates_to_product_reference": "CentOS-Stream-8"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "systemd-libs-0:239-82.el8.1.tuxcare.els1.x86_64 as a component of Community Enterprise Operating System 8",
          "product_id": "CentOS-Stream-8:systemd-libs-0:239-82.el8.1.tuxcare.els1.x86_64"
        },
        "product_reference": "systemd-libs-0:239-82.el8.1.tuxcare.els1.x86_64",
        "relates_to_product_reference": "CentOS-Stream-8"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "systemd-libs-0:239-82.el8.1.tuxcare.els1.i686 as a component of Community Enterprise Operating System 8",
          "product_id": "CentOS-Stream-8:systemd-libs-0:239-82.el8.1.tuxcare.els1.i686"
        },
        "product_reference": "systemd-libs-0:239-82.el8.1.tuxcare.els1.i686",
        "relates_to_product_reference": "CentOS-Stream-8"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "systemd-container-0:239-82.el8.1.tuxcare.els1.i686 as a component of Community Enterprise Operating System 8",
          "product_id": "CentOS-Stream-8:systemd-container-0:239-82.el8.1.tuxcare.els1.i686"
        },
        "product_reference": "systemd-container-0:239-82.el8.1.tuxcare.els1.i686",
        "relates_to_product_reference": "CentOS-Stream-8"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "systemd-container-0:239-82.el8.1.tuxcare.els1.x86_64 as a component of Community Enterprise Operating System 8",
          "product_id": "CentOS-Stream-8:systemd-container-0:239-82.el8.1.tuxcare.els1.x86_64"
        },
        "product_reference": "systemd-container-0:239-82.el8.1.tuxcare.els1.x86_64",
        "relates_to_product_reference": "CentOS-Stream-8"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "systemd-journal-remote-0:239-82.el8.1.tuxcare.els1.x86_64 as a component of Community Enterprise Operating System 8",
          "product_id": "CentOS-Stream-8:systemd-journal-remote-0:239-82.el8.1.tuxcare.els1.x86_64"
        },
        "product_reference": "systemd-journal-remote-0:239-82.el8.1.tuxcare.els1.x86_64",
        "relates_to_product_reference": "CentOS-Stream-8"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "systemd-0:239-82.el8.1.tuxcare.els1.i686 as a component of Community Enterprise Operating System 8",
          "product_id": "CentOS-Stream-8:systemd-0:239-82.el8.1.tuxcare.els1.i686"
        },
        "product_reference": "systemd-0:239-82.el8.1.tuxcare.els1.i686",
        "relates_to_product_reference": "CentOS-Stream-8"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "systemd-0:239-82.el8.1.tuxcare.els1.x86_64 as a component of Community Enterprise Operating System 8",
          "product_id": "CentOS-Stream-8:systemd-0:239-82.el8.1.tuxcare.els1.x86_64"
        },
        "product_reference": "systemd-0:239-82.el8.1.tuxcare.els1.x86_64",
        "relates_to_product_reference": "CentOS-Stream-8"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "systemd-devel-0:239-82.el8.1.tuxcare.els1.x86_64 as a component of Community Enterprise Operating System 8",
          "product_id": "CentOS-Stream-8:systemd-devel-0:239-82.el8.1.tuxcare.els1.x86_64"
        },
        "product_reference": "systemd-devel-0:239-82.el8.1.tuxcare.els1.x86_64",
        "relates_to_product_reference": "CentOS-Stream-8"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "systemd-devel-0:239-82.el8.1.tuxcare.els1.i686 as a component of Community Enterprise Operating System 8",
          "product_id": "CentOS-Stream-8:systemd-devel-0:239-82.el8.1.tuxcare.els1.i686"
        },
        "product_reference": "systemd-devel-0:239-82.el8.1.tuxcare.els1.i686",
        "relates_to_product_reference": "CentOS-Stream-8"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "systemd-udev-0:239-82.el8.1.tuxcare.els1.x86_64 as a component of Community Enterprise Operating System 8",
          "product_id": "CentOS-Stream-8:systemd-udev-0:239-82.el8.1.tuxcare.els1.x86_64"
        },
        "product_reference": "systemd-udev-0:239-82.el8.1.tuxcare.els1.x86_64",
        "relates_to_product_reference": "CentOS-Stream-8"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "systemd-tests-0:239-82.el8.1.tuxcare.els1.x86_64 as a component of Community Enterprise Operating System 8",
          "product_id": "CentOS-Stream-8:systemd-tests-0:239-82.el8.1.tuxcare.els1.x86_64"
        },
        "product_reference": "systemd-tests-0:239-82.el8.1.tuxcare.els1.x86_64",
        "relates_to_product_reference": "CentOS-Stream-8"
      }
    ]
  },
  "vulnerabilities": [
    {
      "cve": "CVE-2026-29111",
      "cwe": {
        "id": "CWE-1287",
        "name": "Improper Validation of Specified Type of Input"
      },
      "notes": [
        {
          "category": "description",
          "text": "systemd, a system and service manager, (as PID 1) hits an assert and freezes execution when an unprivileged IPC API call is made with spurious data. On version v249 and older the effect is not an assert, but stack overwriting, with the attacker controlled content. From version v250 and newer this is not possible as the safety check causes an assert instead. This IPC call was added in v239, so versions older than that are not affected. Versions 260-rc1, 259.2, 258.5, and 257.11 contain patches. No known workarounds are available.",
          "title": "Vulnerability description"
        },
        {
          "category": "general",
          "text": "The CVSS score(s) listed for this vulnerability do not reflect the associated product's status, and are included for informational purposes to better understand the severity of this vulnerability.",
          "title": "CVSS score applicability"
        }
      ],
      "product_status": {
        "fixed": [
          "CentOS-Stream-8:systemd-0:239-82.el8.1.tuxcare.els1.i686",
          "CentOS-Stream-8:systemd-0:239-82.el8.1.tuxcare.els1.x86_64",
          "CentOS-Stream-8:systemd-container-0:239-82.el8.1.tuxcare.els1.i686",
          "CentOS-Stream-8:systemd-container-0:239-82.el8.1.tuxcare.els1.x86_64",
          "CentOS-Stream-8:systemd-devel-0:239-82.el8.1.tuxcare.els1.i686",
          "CentOS-Stream-8:systemd-devel-0:239-82.el8.1.tuxcare.els1.x86_64",
          "CentOS-Stream-8:systemd-journal-remote-0:239-82.el8.1.tuxcare.els1.x86_64",
          "CentOS-Stream-8:systemd-libs-0:239-82.el8.1.tuxcare.els1.i686",
          "CentOS-Stream-8:systemd-libs-0:239-82.el8.1.tuxcare.els1.x86_64",
          "CentOS-Stream-8:systemd-pam-0:239-82.el8.1.tuxcare.els1.x86_64",
          "CentOS-Stream-8:systemd-tests-0:239-82.el8.1.tuxcare.els1.x86_64",
          "CentOS-Stream-8:systemd-udev-0:239-82.el8.1.tuxcare.els1.x86_64"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://cve.tuxcare.com/els/cve/CVE-2026-29111"
        }
      ],
      "release_date": "2026-03-23T22:16:00Z",
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-07-23T13:30:23.010605Z",
          "details": "Details on how to apply the fix are available at: https://cve.tuxcare.com/els/releases/CLSA-2026:1784813417",
          "product_ids": [
            "CentOS-Stream-8:systemd-0:239-82.el8.1.tuxcare.els1.i686",
            "CentOS-Stream-8:systemd-0:239-82.el8.1.tuxcare.els1.x86_64",
            "CentOS-Stream-8:systemd-container-0:239-82.el8.1.tuxcare.els1.i686",
            "CentOS-Stream-8:systemd-container-0:239-82.el8.1.tuxcare.els1.x86_64",
            "CentOS-Stream-8:systemd-devel-0:239-82.el8.1.tuxcare.els1.i686",
            "CentOS-Stream-8:systemd-devel-0:239-82.el8.1.tuxcare.els1.x86_64",
            "CentOS-Stream-8:systemd-journal-remote-0:239-82.el8.1.tuxcare.els1.x86_64",
            "CentOS-Stream-8:systemd-libs-0:239-82.el8.1.tuxcare.els1.i686",
            "CentOS-Stream-8:systemd-libs-0:239-82.el8.1.tuxcare.els1.x86_64",
            "CentOS-Stream-8:systemd-pam-0:239-82.el8.1.tuxcare.els1.x86_64",
            "CentOS-Stream-8:systemd-tests-0:239-82.el8.1.tuxcare.els1.x86_64",
            "CentOS-Stream-8:systemd-udev-0:239-82.el8.1.tuxcare.els1.x86_64"
          ],
          "url": "https://cve.tuxcare.com/els/releases/CLSA-2026:1784813417"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "attackComplexity": "LOW",
            "attackVector": "LOCAL",
            "availabilityImpact": "HIGH",
            "baseScore": 7.8,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "HIGH",
            "integrityImpact": "HIGH",
            "privilegesRequired": "LOW",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "products": [
            "CentOS-Stream-8:systemd-0:239-82.el8.1.tuxcare.els1.i686",
            "CentOS-Stream-8:systemd-0:239-82.el8.1.tuxcare.els1.x86_64",
            "CentOS-Stream-8:systemd-container-0:239-82.el8.1.tuxcare.els1.i686",
            "CentOS-Stream-8:systemd-container-0:239-82.el8.1.tuxcare.els1.x86_64",
            "CentOS-Stream-8:systemd-devel-0:239-82.el8.1.tuxcare.els1.i686",
            "CentOS-Stream-8:systemd-devel-0:239-82.el8.1.tuxcare.els1.x86_64",
            "CentOS-Stream-8:systemd-journal-remote-0:239-82.el8.1.tuxcare.els1.x86_64",
            "CentOS-Stream-8:systemd-libs-0:239-82.el8.1.tuxcare.els1.i686",
            "CentOS-Stream-8:systemd-libs-0:239-82.el8.1.tuxcare.els1.x86_64",
            "CentOS-Stream-8:systemd-pam-0:239-82.el8.1.tuxcare.els1.x86_64",
            "CentOS-Stream-8:systemd-tests-0:239-82.el8.1.tuxcare.els1.x86_64",
            "CentOS-Stream-8:systemd-udev-0:239-82.el8.1.tuxcare.els1.x86_64"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Important"
        }
      ]
    }
  ]
}