oss-sec mailing list archives
Re: Fixed: local root exploit in haveged, fixed in 1.9.21, CVE-2026-41054
From: Hanno Böck <hanno () hboeck de>
Date: Tue, 19 May 2026 15:16:00 +0200
On Tue, 19 May 2026 12:27:03 +0000 Marcus Meissner <meissner () suse de> wrote:
If you are using haveged, todays release fixes a local root exploit.
You can also fix this by uninstalling it. There's no need to have an "entropy daemon"... It adds needless complexity and, as this issue shows, attack surface. There have been many improvements in the Linux kernel's RNG (Jason Donenfeld, also known as the Wireguard developer, did a lot of work on that) and I am quite confident that there are no problems with the RNG on any reasonably recent Linux kernel that an "entropy daemon" would help with. -- Hanno Böck - Independent security researcher https://itsec.hboeck.de/ https://badkeys.info/
Current thread:
- Fixed: local root exploit in haveged, fixed in 1.9.21, CVE-2026-41054 Marcus Meissner (May 19)
- Re: Fixed: local root exploit in haveged, fixed in 1.9.21, CVE-2026-41054 Hanno Böck (May 19)
- Re: Fixed: local root exploit in haveged, fixed in 1.9.21, CVE-2026-41054 Steffen Nurpmeso (May 19)
- Re: Fixed: local root exploit in haveged, fixed in 1.9.21, CVE-2026-41054 nightmare . yeah27 (May 21)
- Re: Re: Fixed: local root exploit in haveged, fixed in 1.9.21, CVE-2026-41054 Jeffrey Walton (May 21)
- CVE-2026-41054: haveged — privilege escalation via command socket Jiri Hladky (May 19)
- Re: Fixed: local root exploit in haveged, fixed in 1.9.21, CVE-2026-41054 Hanno Böck (May 19)
