Symlink Attack Affecting libsystemd package, versions [0,]


Severity

Recommended
0.0
medium
0
10

CVSS assessment by Snyk's Security Team. Learn more

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-CONAN-LIBSYSTEMD-18306313
  • published25 Jul 2026
  • disclosed22 Jul 2026
  • creditUnknown

Introduced: 22 Jul 2026

NewCVE-2026-16552  (opens in a new tab)
CWE-59  (opens in a new tab)

How to fix?

There is no fixed version for libsystemd.

Overview

Affected versions of this package are vulnerable to Symlink Attack through the tmpfiles.d configuration process. An attacker can overwrite arbitrary files by creating a symbolic link that redirects a privileged write operation to a file of their choosing. This is only exploitable if a custom tmpfiles.d entry with the 'w' item type targets a path under /run/user/*, per-user home directories, or other locations where an unprivileged user can influence path resolution.

Workaround

This vulnerability can be mitigated by restricting or auditing any custom tmpfiles.d configuration entries that use the 'w' item type against paths under /run/user/*, per-user home directories, or other locations where an unprivileged user can influence path resolution.

CVSS Base Scores

version 4.0
version 3.1