Critical Exec Privilege Escalation Vulnerability in haveged Affects Multiple Ubuntu Releases

Critical Exec Privilege Escalation Vulnerability in haveged Affects Multiple Ubuntu Releases

First seen 2 Jun 2026, 02:57 UTC UbuntuLinuxsecuritylaunchpad.net 81% similarity 70.5

Article Content

Browse articles
ThreatCluster

A critical security vulnerability has been identified in haveged, a userspace entropy daemon, affecting Ubuntu 26.04 LTS and earlier versions. The flaw allows local attackers to bypass credential checks on the control socket, potentially enabling them to execute commands with elevated privileges. This vulnerability impacts Ubuntu 26.04 LTS, 25.10, 24.04 LTS, and 22.04 LTS. Users are advised to update their systems to the latest package versions to mitigate the risk. The specific package versions required for the fix are detailed in the advisory. After applying updates, a restart of the haveged service is necessary to implement the changes. The vulnerability has been assigned the identifier USN-8358-1. No active exploitation has been reported as of the publication date.

Key Points: • haveged vulnerability allows local privilege escalation on multiple Ubuntu versions. • Affected versions include Ubuntu 26.04 LTS and earlier releases. • Users must update to specific package versions and restart the service to mitigate the risk.

ThreatCluster AI

Timeline

2026-06-01
USN-8358-1 published
Ubuntu issued a security notice detailing a critical vulnerability in haveged affecting multiple versions.
Ubuntu
2026-06-01
Vulnerability discovered
The flaw in haveged was found to incorrectly handle credential checks, allowing privilege escalation.
Linuxsecurity
Recent
Users advised to update
Users are urged to update to the latest package versions to address the critical vulnerability.
Linuxsecurity

Community

Browse all →

Tracked Entities in This Story