In systemd 259, systemd-journald can send ANSI escape sequences to the terminals of arbitrary users when a "logger -p emerg" command is executed, if ForwardToWall=yes is set.
History

Mon, 13 Apr 2026 13:00:00 +0000

Type Values Removed Values Added
First Time appeared Systemd
Systemd systemd
Vendors & Products Systemd
Systemd systemd

Mon, 13 Apr 2026 12:15:00 +0000

Type Values Removed Values Added
Title systemd: systemd-journald: Unintended output to user terminals via logger command
Weaknesses CWE-117
References
Metrics threat_severity

None

threat_severity

Low


Fri, 10 Apr 2026 18:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 10 Apr 2026 16:00:00 +0000

Type Values Removed Values Added
Description In systemd 259, systemd-journald can send ANSI escape sequences to the terminals of arbitrary users when a "logger -p emerg" command is executed, if ForwardToWall=yes is set.
Weaknesses CWE-669
References
Metrics cvssV3_1

{'score': 2.9, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2026-04-10T15:48:44.215Z

Updated: 2026-04-10T17:27:22.882Z

Reserved: 2026-04-10T15:48:43.773Z

Link: CVE-2026-40228

cve-icon Vulnrichment

Updated: 2026-04-10T17:27:12.048Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-04-10T16:16:33.753

Modified: 2026-04-13T15:02:06.187

Link: CVE-2026-40228

cve-icon Redhat

Severity : Low

Publid Date: 2026-04-10T15:48:44Z

Links: CVE-2026-40228 - Bugzilla