Linuxsecurity
Critical Exec Privilege Escalation Vulnerability in haveged Affects Multiple Ubuntu Releases
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
A critical security vulnerability has been identified in haveged, a userspace entropy daemon, affecting Ubuntu 26.04 LTS and earlier versions. The flaw allows local attackers to bypass credential checks on the control socket, potentially enabling them to execute commands with elevated privileges. This vulnerability impacts Ubuntu 26.04 LTS, 25.10, 24.04 LTS, and 22.04 LTS. Users are advised to update their systems to the latest package versions to mitigate the risk. The specific package versions required for the fix are detailed in the advisory. After applying updates, a restart of the haveged service is necessary to implement the changes. The vulnerability has been assigned the identifier USN-8358-1. No active exploitation has been reported as of the publication date.
Key Points: • haveged vulnerability allows local privilege escalation on multiple Ubuntu versions. • Affected versions include Ubuntu 26.04 LTS and earlier releases. • Users must update to specific package versions and restart the service to mitigate the risk.