Missing exit out of permission check in haveged could lead to root exploit
21Vexday Risk Score
Sem sinal de exploração. Nenhum artefato público de exploração conhecido até agora.
ssvc Trackcvss 7.8epss 0.2%
probabilidade de exploração
0.2%top 92% das CVEs
exploração observada
nãonenhuma fonte reporta
In `src/havegecmd.c`, the `socket_handler` function performs a credential check on the abstract UNIX socket (`\0/sys/entropy/haveged`). However, while it detects if the connecting user is not root (`cred.uid != 0`) and prepares a negative acknowledgement (`ASCII_NAK`), it **fails to stop execution**. The code proceeds to the `switch` statement, allowing any local unprivileged user to execute privileged commands such as `MAGIC_CHROOT`.
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Produtos afetados
SUSE · Container suse/sle-micro/5.5:latestSUSE · Container suse/sle-micro-rancher/5.3:latestSUSE · Container suse/sle-micro-rancher/5.4:latestSUSE · Image SLES15-SP4-SAP-BYOSSUSE · Image SLES15-SP4-SAP-BYOS-AzureSUSE · Image SLES15-SP4-SAP-BYOS-EC2SUSE · Image SLES15-SP4-SAP-BYOS-GCESUSE · Image SLES15-SP4-SAP-HardenedSUSE · Image SLES15-SP4-SAP-Hardened-BYOSSUSE · Image SLES15-SP4-SAP-Hardened-BYOS-AzureSUSE · Image SLES15-SP4-SAP-Hardened-BYOS-EC2SUSE · Image SLES15-SP4-SAP-Hardened-BYOS-GCESUSE · Image SLES15-SP4-SAP-Hardened-GCESUSE · SUSE Linux Enterprise Desktop 15 SP7SUSE · SUSE Linux Enterprise High Performance Computing 15 SP4-ESPOSSUSE · SUSE Linux Enterprise High Performance Computing 15 SP4-LTSSSUSE · SUSE Linux Enterprise High Performance Computing 15 SP5-ESPOSSUSE · SUSE Linux Enterprise High Performance Computing 15 SP5-LTSSSUSE · SUSE Linux Enterprise High Performance Computing 15 SP7SUSE · SUSE Linux Enterprise Micro 5.3SUSE · SUSE Linux Enterprise Micro 5.4SUSE · SUSE Linux Enterprise Micro 5.5SUSE · SUSE Linux Enterprise Module for Basesystem 15 SP7SUSE · SUSE Linux Enterprise Server 15 SP4-LTSSSUSE · SUSE Linux Enterprise Server 15 SP5-LTSSSUSE · SUSE Linux Enterprise Server 15 SP6-LTSSSUSE · SUSE Linux Enterprise Server 15 SP7SUSE · SUSE Linux Enterprise Server for SAP Applications 15 SP4SUSE · SUSE Linux Enterprise Server for SAP Applications 15 SP5SUSE · SUSE Linux Enterprise Server for SAP Applications 15 SP6SUSE · SUSE Linux Enterprise Server for SAP Applications 15 SP7SUSE · SUSE Manager Proxy LTS 4.3SUSE · SUSE Manager Retail Branch Server LTS 4.3SUSE · SUSE Manager Server LTS 4.3Referências
https://bugzilla.suse.com/show_bug.cgi?id=CVE-2026-41054https://lists.debian.org/debian-lts-announce/2026/06/msg00005.htmlhttp://www.openwall.com/lists/oss-security/2026/05/19/3http://www.openwall.com/lists/oss-security/2026/05/19/4http://www.openwall.com/lists/oss-security/2026/05/19/5http://www.openwall.com/lists/oss-security/2026/05/20/1http://www.openwall.com/lists/oss-security/2026/05/21/17http://www.openwall.com/lists/oss-security/2026/05/22/1