CVE-2026-15059
Description
A flaw was found in systemd-oomd. Local unprivileged users can exploit a missing path traversal validation in the systemd-oomd Inter-Process Communication (IPC) Application Programming Interface (API). This vulnerability allows them to terminate arbitrary local processes, leading to a denial of service.
Statement
systemd-oomd is vulnerable to a path traversal in its Varlink ManagedOOM IPC handler: an unprivileged local user can supply a crafted cgroup path containing ../ sequences that, after path_simplify(), escapes the /sys/fs/cgroup hierarchy, allowing the daemon to act on — and terminate the processes of — an arbitrary cgroup the caller does not own (CWE-22).
Red Hat rates this Moderate (CVSS 5.5, AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H), consistent with the upstream advisory (GHSA-652q-wxr6-h5j6). Exploitation is bounded by significant runtime preconditions: it requires a local unprivileged account, the systemd-oomd service must be actively running (it is not enabled by default on Red Hat Enterprise Linux server installations), the attacker must reach the ManagedOOM Varlink socket, and must know the target PID/cgroup. Impact is limited to availability (process termination); there is no confidentiality or integrity impact.
Affected Red Hat products ship systemd >= 250 (RHEL 9 / 10, RHIVOS). Releases shipping systemd < 250 (RHEL 7 with systemd 219, RHEL 8 with systemd 239) are not affected — the vulnerable oomd cgroup-path handling was introduced in systemd 250 and the code is not present in those versions.
Mitigation
On systems that do not require memory-pressure-based OOM management, disable the systemd-oomd service to remove the attack surface entirely:
systemctl disable --now systemd-oomd.service
Where systemd-oomd must remain enabled, restrict local access to untrusted users. Note that on Red Hat Enterprise Linux server profiles systemd-oomd is not enabled by default, so default server installations are not exposed until the service is explicitly started.
Common Vulnerability Scoring System (CVSS) Score Details
Info alert:Important note
CVSS scores for open source components depend on vendor-specific factors (e.g. version or build chain). Therefore, Red Hat's score and impact rating can be different from NVD and other vendors. Red Hat remains the authoritative CVE Naming Authority (CNA) source for its products and services (see Red Hat classifications).
CVSS v3 Score Breakdown
| Red Hat | NVD | cve.org | |
|---|---|---|---|
| Base Score | 5.5 | N/A | 5.5 |
| Attack Vector | Local | N/A | Local |
| Attack Complexity | Low | N/A | Low |
| Privileges Required | Low | N/A | Low |
| User Interaction | None | N/A | None |
| Scope | Unchanged | N/A | Unchanged |
| Confidentiality | None | N/A | None |
| Integrity Impact | None | N/A | None |
| Availability Impact | High | N/A | High |
Vector
Red Hat: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
cve.org: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Understanding the Weakness (CWE)
Integrity,Confidentiality,Availability
Technical Impact: Execute Unauthorized Code or Commands
The attacker may be able to create or overwrite critical files that are used to execute code, such as programs or libraries.
Integrity
Technical Impact: Modify Files or Directories
The attacker may be able to overwrite or create critical files, such as programs, libraries, or important data. If the targeted file is used for a security mechanism, then the attacker may be able to bypass that mechanism. For example, appending a new account at the end of a password file may allow an attacker to bypass authentication.
Confidentiality
Technical Impact: Read Files or Directories
The attacker may be able read the contents of unexpected files and expose sensitive data. If the targeted file is used for a security mechanism, then the attacker may be able to bypass that mechanism. For example, by reading a password file, the attacker could conduct brute force password guessing attacks in order to break into an account on the system.
Availability
Technical Impact: DoS: Crash, Exit, or Restart
The attacker may be able to overwrite, delete, or corrupt unexpected critical files such as programs, libraries, or important data. This may prevent the product from working at all and in the case of protection mechanisms such as authentication, it has the potential to lock out product users.
Frequently Asked Questions
Not sure what something means? Check out our Security Glossary.
Want to get errata notifications? Sign up here.