Skip to content
Critical Exec Privilege Escalation Vulnerability in haveged Affects Multiple Ubuntu Releases

Critical Exec Privilege Escalation Vulnerability in haveged Affects Multiple Ubuntu Releases

First seen 2 Jun 2026, 02:57 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster June 3, 2026 at 02:38 UTC

A critical security vulnerability has been identified in haveged, a userspace entropy daemon, affecting Ubuntu 26.04 LTS and earlier versions. The flaw allows local attackers to bypass credential checks on the control socket, potentially enabling them to execute commands with elevated privileges. This vulnerability impacts Ubuntu 26.04 LTS, 25.10, 24.04 LTS, and 22.04 LTS. Users are advised to update their systems to the latest package versions to mitigate the risk. The specific package versions required for the fix are detailed in the advisory. After applying updates, a restart of the haveged service is necessary to implement the changes. The vulnerability has been assigned the identifier USN-8358-1. No active exploitation has been reported as of the publication date.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 111d ago How this analysis works

Timeline

2026-06-01
USN-8358-1 published
Ubuntu issued a security notice detailing a critical vulnerability in haveged affecting multiple versions.
Ubuntu
2026-06-01
Vulnerability discovered
The flaw in haveged was found to incorrectly handle credential checks, allowing privilege escalation.
Linuxsecurity
Recent
Users advised to update
Users are urged to update to the latest package versions to address the critical vulnerability.
Linuxsecurity

More articles in this cluster (3)

Following this threat?

Track Ubuntu in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed