Security update for systemd
This update for systemd fixes the following issues: Changes in systemd: - Better handle TLS allocation failure (bsc#1254924). - Disable mounting `debugfs` by default (jsc#PED-8812). - Import commit 9e8b5afe0fb2061f4a17a3022469dd62f2683960 (bsc#1267647 bsc#1267644 bsc#1262305 bsc#1263117). - Move `systemd-pcrlock` out from the experimental sub-package to `udev` (bsc#1248261 jsc#PED-15946). - Add a weak runtime dependency on `libtss2-tcti-device0` (bsc#1260357). - Import commit 59336000ef7850eba0963c6a690ff3371c425929 (bsc#1261982 bsc#1261983). - Add a weak runtime dependency on `polkit` (bsc#1259071). - systemd-update-helper: fix the clean-state command only removing `$STATE_DIR/system` instead of `$STATE_DIR/`. - systemd-update-helper: add `--root` option for testing convenience. - systemd-update-helper: fix incorrect skipping of `systemctl disable` during package removal (bsc#1245551). - systemd-update-helper: fix `do_install_units()` incorrectly returning 1 when no units need preset. - systemd.spec: introduce `%bcond_without` docs to allow skipping man pages and `devel-doc`. - systemd.spec: drop the `%{release}` number from the SBAT version (bsc#1251948).
Security update for systemd
Description
This update for systemd fixes the following issues: Changes in systemd: - Better handle TLS allocation failure (bsc#1254924). - Disable mounting `debugfs` by default (jsc#PED-8812). - Import commit 9e8b5afe0fb2061f4a17a3022469dd62f2683960 (bsc#1267647 bsc#1267644 bsc#1262305 bsc#1263117). - Move `systemd-pcrlock` out from the experimental sub-package to `udev` (bsc#1248261 jsc#PED-15946). - Add a weak runtime dependency on `libtss2-tcti-device0` (bsc#1260357). - Import commit 59336000ef7850eba0963c6a690ff3371c425929 (bsc#1261982 bsc#1261983). - Add a weak runtime dependency on `polkit` (bsc#1259071). - systemd-update-helper: fix the clean-state command only removing `$STATE_DIR/system` instead of `$STATE_DIR/`. - systemd-update-helper: add `--root` option for testing convenience. - systemd-update-helper: fix incorrect skipping of `systemctl disable` during package removal (bsc#1245551). - systemd-update-helper: fix `do_install_units()` incorrectly returning 1 when no units need preset. - systemd.spec: introduce `%bcond_without` docs to allow skipping man pages and `devel-doc`. - systemd.spec: drop the `%{release}` number from the SBAT version (bsc#1251948).
Affected software
Technical Details
- Gcve Source
- db.gcve.eu
- Csaf Category
- csaf_security_advisory
- Csaf Version
- 2.0
- Publisher
- SUSE Product Security Team
- Advisory Id
- openSUSE-SU-2026:21222-1
- Cve Count
- 0
Threat ID: 6aab497155bf5e2cf5990e09
Added to database: 09/17/2026, 01:59:13 UTC
Last updated: 09/17/2026, 02:02:24 UTC
Views: 1
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.