A local privilege-escalation flaw in the Linux entropy daemon haveged was disclosed as CVE-2026-41054, allowing unprivileged local users to interact with a root-running daemon over its abstract UNIX command socket and trigger privileged operations. The bug affects releases from 1.9.14 with command socket support enabled, with broader discussion noting the underlying logic error was introduced earlier in the 1.9.x series, and it was fixed in haveged 1.9.21. In socket_handler() in src/havegecmd.c, the daemon checked SO_PEERCRED and sent a negative acknowledgment to non-root callers, but failed to exit the function, so processing continued into privileged command handling and exposed commands such as MAGIC_CHROOT and MAGIC_CLOSE.
The issue was reported by Dirk Müller of SUSE and disclosed through SUSE Bugzilla and the oss-sec mailing list, where maintainers urged users to upgrade to 1.9.21 or remove haveged entirely. The fix added an explicit exit after the NAK response and moved credential validation ahead of command parsing as a defense-in-depth measure. Follow-up discussion on oss-sec argued that modern Linux kernels have reduced the need for entropy daemons like haveged, and that keeping such software installed can unnecessarily expand system attack surface.

Get the actors, campaigns, and ATT&CK mapping behind it.
8 events from the most recent confirmed update back to the earliest known activity.
Red Hat Bugzilla stated that Fedora and EPEL released fixed haveged packages for multiple supported releases in response to CVE-2026-41054, including a backported patch for EPEL 8. The advisory also reiterated that upstream had fixed the flaw in haveged 1.9.21.
Jiri Hladky publicly disclosed technical details of CVE-2026-41054 on oss-sec, explaining that socket_handler() failed to return after rejecting non-root callers. The disclosure described how unprivileged local users could send MAGIC_CHROOT or MAGIC_CLOSE commands to the root-running daemon.
SUSE published security advisories and released updated haveged packages for multiple openSUSE Leap and SUSE Linux Enterprise products in response to CVE-2026-41054. The Bugzilla entry tied the updates to the local privilege-escalation flaw in haveged's command socket handling.
Marcus Meissner disclosed on the oss-sec mailing list that a local root exploit in haveged had been fixed in release 1.9.21 and advised users to update or uninstall the software. The issue was identified as CVE-2026-41054.
The vulnerability was fixed in haveged version 1.9.21 by adding a return path after sending a NAK to unauthorized callers and moving the credential check before command parsing as defense in depth. Affected versions were described as 1.9.14 and later with command socket support.
SUSE published Bugzilla issue 1264086 for CVE-2026-41054, describing a missing exit after a permission check in haveged that could lead to root exploitation. This documented the vulnerability in SUSE's tracking system.
Dirk Müller of SUSE reported the privilege-escalation issue affecting haveged's command socket handling. The flaw was later tracked as CVE-2026-41054.
The vulnerable command socket logic was introduced in haveged version 1.9.3, where non-root callers could receive a NAK but execution continued into privileged command handling. This created the basis for a local root exploit via the daemon's abstract UNIX socket.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Get the adversaries, campaigns, and ATT&CK mapping behind this technique, with detections ready to deploy.
12 references tracked. Mallory keeps watching after this page renders.
seclists.org
Open sourceseclists.org
Open sourcebugzilla.redhat.com
Open sourceseclists.org
Open sourcebugzilla.suse.com
Open sourceopenwall.com
Open sourcesecurity-tracker.debian.org
Open sourcelists.debian.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.