CVE-2026-41054
Publication date 20 May 2026
Last updated 2 June 2026
Ubuntu priority
Cvss 3 Severity Score
Description
In `src/havegecmd.c`, the `socket_handler` function performs a credential check on the abstract UNIX socket (`\0/sys/entropy/haveged`). However, while it detects if the connecting user is not root (`cred.uid != 0`) and prepares a negative acknowledgement (`ASCII_NAK`), it **fails to stop execution**. The code proceeds to the `switch` statement, allowing any local unprivileged user to execute privileged commands such as `MAGIC_CHROOT`.
Status
| Package | Ubuntu Release | Status |
|---|---|---|
| haveged | 26.04 LTS resolute |
Fixed 1.9.19-14ubuntu0.1
|
| 25.10 questing |
Fixed 1.9.19-12+deb13u1build0.25.10.1
|
|
| 24.04 LTS noble |
Fixed 1.9.14-1ubuntu2+esm1~24.04.1
|
|
| 22.04 LTS jammy |
Fixed 1.9.14-1ubuntu1+esm1~22.04.1
|
|
| 20.04 LTS focal |
Not affected
|
|
| 18.04 LTS bionic |
Not affected
|
|
| 14.04 LTS trusty |
Not affected
|
Get expanded security coverage with Ubuntu Pro
Reduce your average CVE exposure time from 98 days to 1 day with expanded CVE patching, ten-years security maintenance and optional support for the full stack of open-source applications. Free for personal use.
Get Ubuntu Pro 30-day free trialSeverity score breakdown
| Parameter | Value |
|---|---|
| Base score |
|
| Attack vector | Local |
| Attack complexity | Low |
| Privileges required | Low |
| User interaction | None |
| Scope | Unchanged |
| Confidentiality | High |
| Integrity impact | High |
| Availability impact | High |
| Vector | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
References
Related Ubuntu Security Notices (USN)
- USN-8358-1
- haveged vulnerability
- 1 June 2026
Other references
- https://www.cve.org/CVERecord?id=CVE-2026-41054
- https://bugzilla.suse.com/show_bug.cgi?id=1264086
- https://bugzilla.suse.com/show_bug.cgi?id=CVE-2026-41054
- http://www.openwall.com/lists/oss-security/2026/05/19/3
- http://www.openwall.com/lists/oss-security/2026/05/19/4
- http://www.openwall.com/lists/oss-security/2026/05/19/5
- http://www.openwall.com/lists/oss-security/2026/05/20/1