[ GLSA 202608-11 ] haveged: Privilege escalation
| Newsgroups | gmane.linux.gentoo.announce |
|---|---|
| Message-ID | <178675302508.1.12319724658627806319@cdebd0f5f1fc> |
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
Gentoo Linux Security Advisory GLSA 202608-11
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
https://security.gentoo.org/
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
Severity: High
Title: haveged: Privilege escalation
Date: August 15, 2026
Bugs: #975496
ID: 202608-11
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
Synopsis
========
A vulnerability has been discovered in haveged which could allow local
privilege escalation
Background
==========
haveged is a simple entropy daemon using the HAVEGE algorithm.
Affected packages
=================
Package Vulnerable Unaffected
---------------- ------------ ------------
sys-apps/haveged < 1.9.21 >= 1.9.21
Description
===========
A vulnerability has been discovered in haveged. Please review the CVE
identifier referenced below for details.
Impact
======
Root privilege escalation may be achieved by an attacker.
Workaround
==========
There is no known workaround at this time.
Resolution
==========
All haveged users should upgrade to the latest version:
# emerge --sync
# emerge --ask --oneshot --verbose ">=sys-apps/haveged-1.9.21"
Alternatively, consider not using haveged anymore on modern Linux kernel
versions, per https://www.openwall.com/lists/oss-security/2026/05/19/4
References
==========
[ 1 ] CVE-2026-41054
https://nvd.nist.gov/vuln/detail/CVE-2026-41054
Availability
============
This GLSA and any updates to it are available for viewing at
the Gentoo Security Website:
https://security.gentoo.org/glsa/202608-11
Concerns?
=========
Security is a primary focus of Gentoo Linux and ensuring the
confidentiality and security of our users' machines is of utmost
importance to us. Any security concerns should be addressed to
[email protected] or alternatively, you may file a bug at
https://bugs.gentoo.org.
License
=======
Copyright 2026 Gentoo Foundation, Inc; referenced text
belongs to its owner(s).
The contents of this document are licensed under the
Creative Commons - Attribution / Share Alike license.
https://creativecommons.org/licenses/by-sa/2.5
signature.asc
(application/pgp-signature, 870 B)
-----BEGIN PGP SIGNATURE----- iQJPBAEBCAA5FiEEpqTA6ABLMxh/aChGFMQkOaVy+9kFAmp/sAAbFIAAAAAABAAO bWFudTIsMi41KzEuMTIsMiwyAAoJEBTEJDmlcvvZodQP+QHkliv1bkMVXwpKAkbC BgkTvNFjmN8uU1dlHhPbeibYcSZ/m+sEKo/pbe11hfzhyq4Uem5GB326F++/Cv99 Tf6VKYlZZIpViaObF/SUGaVEG0EdN1lWUopSTj6Ted1W/ZAVIDe4wqzR89GQmDIl AsGjcCQ/nDP1cEbun4mIoPNbm9oMUycF+4KAYJmO6aubLp/eapDWF7lxK3Ov4fEk YxLLAUAsTAKsD0ns65o5BEP82ZPtkikhJQfPz18OOja61ho7S7scwCutx7cGnazv KsPU/LRnwOOP6m2nJQhclKR/xELCkj7nj9Xo4ne/0+Kiqf1yC2tK0mz+PN3BFvLF NFx4RUaA73ptNqIP8sSy5oYpBeGcBMAmYTx8JQuEeLXzLExVZ/YfLiFlkTtxyaFr sttdy1JZFdLPu5iEvnTyGZsfycaGlyx1cz9dpROVOWg7wIhiJp8c4+I+ZVo1a/pQ ooftKZyTao/6jXWQO+i92fcFsirj7ac0PMHUjzSkes+jQnW7gvICVgvsp5pprfi5 6gjb+TkoG7Em/JV7qZZHP4DPpZ20i70peVzVxv6jNd+7nc6UJAmusoj8L2IDtUPW ACYDFO4cFAsnkS6JFmaRrqpC87j0AI0+7Qf7YX7+rBQfVG0UDVzH5bpGtG1fqPMI 2w+PpeJdRfd8fhIdQq1jfCCw =bOYY -----END PGP SIGNATURE-----