CVE-2026-15059

Description

A flaw was found in systemd-oomd. Local unprivileged users can exploit a missing path traversal validation in the systemd-oomd Inter-Process Communication (IPC) Application Programming Interface (API). This vulnerability allows them to terminate arbitrary local processes, leading to a denial of service.

Statement

systemd-oomd is vulnerable to a path traversal in its Varlink ManagedOOM IPC handler: an unprivileged local user can supply a crafted cgroup path containing ../ sequences that, after path_simplify(), escapes the /sys/fs/cgroup hierarchy, allowing the daemon to act on — and terminate the processes of — an arbitrary cgroup the caller does not own (CWE-22).

Red Hat rates this Moderate (CVSS 5.5, AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H), consistent with the upstream advisory (GHSA-652q-wxr6-h5j6). Exploitation is bounded by significant runtime preconditions: it requires a local unprivileged account, the systemd-oomd service must be actively running (it is not enabled by default on Red Hat Enterprise Linux server installations), the attacker must reach the ManagedOOM Varlink socket, and must know the target PID/cgroup. Impact is limited to availability (process termination); there is no confidentiality or integrity impact.

Affected Red Hat products ship systemd >= 250 (RHEL 9 / 10, RHIVOS). Releases shipping systemd < 250 (RHEL 7 with systemd 219, RHEL 8 with systemd 239) are not affected — the vulnerable oomd cgroup-path handling was introduced in systemd 250 and the code is not present in those versions.

Mitigation

On systems that do not require memory-pressure-based OOM management, disable the systemd-oomd service to remove the attack surface entirely:

    systemctl disable --now systemd-oomd.service

Where systemd-oomd must remain enabled, restrict local access to untrusted users. Note that on Red Hat Enterprise Linux server profiles systemd-oomd is not enabled by default, so default server installations are not exposed until the service is explicitly started.

Common Vulnerability Scoring System (CVSS) Score Details

Info alert:Important note

CVSS scores for open source components depend on vendor-specific factors (e.g. version or build chain). Therefore, Red Hat's score and impact rating can be different from NVD and other vendors. Red Hat remains the authoritative CVE Naming Authority (CNA) source for its products and services (see Red Hat classifications).

CVSS v3 Score Breakdown

Red HatNVDcve.org
Base Score5.5N/A5.5
Attack VectorLocalN/ALocal
Attack ComplexityLowN/ALow
Privileges RequiredLowN/ALow
User InteractionNoneN/ANone
ScopeUnchangedN/AUnchanged
ConfidentialityNoneN/ANone
Integrity ImpactNoneN/ANone
Availability ImpactHighN/AHigh

Vector

Red Hat: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

cve.org: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Understanding the Weakness (CWE)

Integrity,Confidentiality,Availability

Technical Impact: Execute Unauthorized Code or Commands

The attacker may be able to create or overwrite critical files that are used to execute code, such as programs or libraries.

Integrity

Technical Impact: Modify Files or Directories

The attacker may be able to overwrite or create critical files, such as programs, libraries, or important data. If the targeted file is used for a security mechanism, then the attacker may be able to bypass that mechanism. For example, appending a new account at the end of a password file may allow an attacker to bypass authentication.

Confidentiality

Technical Impact: Read Files or Directories

The attacker may be able read the contents of unexpected files and expose sensitive data. If the targeted file is used for a security mechanism, then the attacker may be able to bypass that mechanism. For example, by reading a password file, the attacker could conduct brute force password guessing attacks in order to break into an account on the system.

Availability

Technical Impact: DoS: Crash, Exit, or Restart

The attacker may be able to overwrite, delete, or corrupt unexpected critical files such as programs, libraries, or important data. This may prevent the product from working at all and in the case of protection mechanisms such as authentication, it has the potential to lock out product users.

Frequently Asked Questions

Want to get errata notifications? Sign up here.