VDB

CVE-2026-41054

CVE-2026-41054 PUBLISHED CVSS 7.800000190734863 HIGH

In `src/havegecmd.c`, the `socket_handler` function performs a credential check on the abstract UNIX socket (`\0/sys/entropy/haveged`). However, while it detects if the connecting user is not root (`cred.uid != 0`) and prepares a negative acknowledgement (`ASCII_NAK`), it **fails to stop execution**. The code proceeds to the `switch` statement, allowing any local unprivileged user to execute privileged commands such as `MAGIC_CHROOT`.

EPSS 0.00% · 0.2th percentile

Risk Scores

CVSS v3.1
7.800000190734863
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS Score
0.00%
0.2th percentile

Affected Products

VendorProductVersions
SUSESUSE Linux Enterprise Server for SAP Applications 15 SP7?
SUSEImage SLES15-SP4-SAP-Hardened-GCE?
SUSEImage SLES15-SP4-SAP-BYOS?
SUSESUSE Linux Enterprise High Performance Computing 15 SP4-LTSS?
SUSESUSE Linux Enterprise High Performance Computing 15 SP5-LTSS?
SUSEImage SLES15-SP4-SAP-Hardened-BYOS?
SUSESUSE Linux Enterprise Server 15 SP4-LTSS?
SUSESUSE Linux Enterprise Module for Basesystem 15 SP7?
SUSEImage SLES15-SP4-SAP-BYOS-Azure?
SUSESUSE Manager Proxy LTS 4.3?
SUSEImage SLES15-SP4-SAP-Hardened-BYOS-GCE?
SUSEImage SLES15-SP4-SAP-Hardened-BYOS-Azure?
SUSESUSE Linux Enterprise High Performance Computing 15 SP4-ESPOS?
SUSESUSE Linux Enterprise High Performance Computing 15 SP4-ESPOS?
SUSEImage SLES15-SP4-SAP-BYOS-GCE?
SUSESUSE Manager Server LTS 4.3?
SUSEImage SLES15-SP4-SAP-BYOS-GCE?
SUSESUSE Linux Enterprise Module for Basesystem 15 SP7?
SUSESUSE Linux Enterprise Server 15 SP5-LTSS?
SUSESUSE Linux Enterprise Server 15 SP6-LTSS?

…and 66 more

Timeline

  • May 19, 2026 PoC Published
  • May 19, 2026 PoC Published
  • May 20, 2026 EPSS Score
  • May 20, 2026 PoC Published
  • May 20, 2026 PoC Published
  • May 20, 2026 PoC Published
  • May 20, 2026 CVE Published
  • May 20, 2026 PoC Published
  • May 21, 2026 EPSS Score
  • May 21, 2026 Coalition ESS Score
  • May 21, 2026 Security Advisory
  • May 22, 2026 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›