CVE-2026-41054Disclosure

LOWCVSS 7.8 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

In `src/havegecmd.c`, the `socket_handler` function performs a credential check on the abstract UNIX socket (`\0/sys/entropy/haveged`). However, while it detects if the connecting user is not root (`cred.uid != 0`) and prepares a negative acknowledgement (`ASCII_NAK`), it **fails to stop execution**. The code proceeds to the `switch` statement, allowing any local unprivileged user to execute privileged commands such as `MAGIC_CHROOT`.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-305

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 5 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 5 signals
  • Disclosure: 3 classified signals
  • Peaked 2d ago at 2 mentions (2026-05-20); latest day: 1
  • 5 total mentions across 3 days

Deep dive

Activity timeline5 mentions / 3d
01122Mentions · 2026-05-20: 2Mentions · 2026-05-24: 2Mentions · 2026-06-08: 1Patch / Workaround · 2026-05-24: 2Technical Details · 2026-05-20: 2Technical Details · 2026-05-24: 2Technical Details · 2026-06-08: 105-2005-2406-08
Signal classification2 categories
Disclosure
360.0%
Patch
240.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-05-202
Disclosure2
2026-05-242
Patch2
2026-06-081
Disclosure1
Full discourse5 posts
  • Open Source Security mailing list@oss_security
    Disclosure

    CVE-2026-41054: haveged: Privilege escalation via command socket https://www.openwall.com/lists/oss-security/2026/05/19/3 checks the connecting peer's uid via SO_PEERCRED and sends a NAK response to non-root callers. However, after sending the NAK, execution continued, allowing for a local root exploit.

    Post summary

    The post announces a privilege‑escalation bug in haveged’s command socket that allows local root after a NAK response; no PoC, exploit code, or patch is discussed.

    010821.3K
    4.7K followersView on X
  • Ferramentas Linux@Cezar_H_Linux
    Disclosure

    🚨 Alerta: O haveged (daemon de entropia do Linux) teve uma falha crítica de escalonamento de privilégios (CVE-2026-41054) Saiba mais: -> http://tinyurl.com/3296rhht #Fedora https://t.co/ogtbR7XgVT

    Post summary

    An alert announces a critical privilege‑escalation vulnerability (CVE-2026-41054) affecting the haveged Linux entropy daemon.

    1004087
    1.5K followersView on X
  • Andre Gironda@AndreGironda
    Disclosure

    Jiri Hladky publicly disclosed technical details of CVE-2026-41054 haveged privilege escalation via command socket -- https://seclists.org/oss-sec/2026/q2/615

    Post summary

    Jiri Hladky publicly disclosed technical details of CVE-2026-41054, a haveged privilege escalation via command socket, but did not provide a PoC, exploit code, patch, or report on active exploitation.

    10010157
    3.8K followersView on X
  • Ferramentas Linux@Cezar_H_Linux
    Patch

    CVE-2026-41054: local user → root via haveged. Patch is out. But next month, another CVE will appear. Read more -> http://tinyurl.com/3jx4svhy #Debian https://t.co/mX2mTkKe9h

    Post summary

    The post announces CVE‑2026‑41054, confirms that a patch has been released, and briefly notes the upcoming CVE, without providing exploit code or evidence of active attacks.

    1000072
    1.5K followersView on X
  • Ferramentas Linux@Cezar_H_Linux
    Patch

    CVE-2026-41054: local user → root via haveged. Patch is out. But next month, another CVE will appear. Read more -> http://tinyurl.com/3jx4svhy #Debian

    Post summary

    The post alerts that CVE-2026-41054 is a local privilege escalation in haveged, a patch has been released, and further details can be found via a provided link.

    1000080
    1.5K followersView on X

Explore more