USN-8626-1: systemd vulnerabilities
It was discovered that systemd-homed did not properly verify the signature
of home records. A local attacker could possibly use this issue to add
arbitrary system groups to a logged-in user and gain elevated privileges.
(CVE-2026-16742)
It was discovered that systemd-machined incorrectly handled certain polkit
authorization checks. A local attacker could possibly use this issue to
terminate arbitrary processes, including privileged ones. This issue only
affected Ubuntu 26.04 LTS. (CVE-2026-15060)
It was discovered that systemd-oomd did not properly validate certain IPC
requests. A local attacker could possibly use this issue to terminate
arbitrary processes. (CVE-2026-15059)