In udev in systemd before 260, local root execution can occur via malicious hardware devices and unsanitized kernel output.
https://www.helpnetsecurity.com/2026/05/18/debian-13-5-released/
https://github.com/systemd/systemd/security/advisories/GHSA-vpfq-8p5f-jcqx