Security News

Cybersecurity news aggregator

🐧
HIGH Vulnerabilities Gentoo GLSA

GLSA 202608-11: haveged: Privilege escalation

A local privilege escalation vulnerability (CVE-2026-41054, CVSS 7.8 High) in the haveged entropy daemon allows attackers to gain root privileges. The vulnerability affects haveged versions prior to 1.9.21, and users must upgrade to version 1.9.21 to remediate the issue. No workaround is currently known, though the advisory suggests evaluating the continued need for haveged on modern Linux kernels.
Read Full Article →

A vulnerability has been discovered in haveged which could allow local privilege escalation Affected packages Package sys-apps/haveged on all architectures Affected versions < 1.9.21 Unaffected versions >= 1.9.21 Background haveged is a simple entropy daemon using the HAVEGE algorithm. Description A vulnerability has been discovered in haveged. Please review the CVE identifier referenced below for details. Impact Root privilege escalation may be achieved by an attacker. Workaround There is no known workaround at this time. Resolution All haveged users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose ">=sys-apps/haveged-1.9.21" Alternatively, consider not using haveged anymore on modern Linux kernel versions, per https://www.openwall.com/lists/oss-security/2026/05/19/4 References CVE-2026-41054 Release date August 15, 2026 Latest revision August 15, 2026: 1 Severity high Exploitable local Bugzilla entries 975496

Share this article