Alerts This Week
Warning Icon 1 474
Alerts This Week
Warning Icon 1 474

openSUSE 2026 2009-1 Important Haveged Root Exploit CVE-2026-41054

suse
Calendar Grey May 19, 2026
Dist Suse Esm H88
An important security update for haveged identifies a root exploit risk. Details on patching available.
An update that solves one vulnerability can now be installed.

Summary

## This update for haveged fixes the following issue * CVE-2026-41054: missing exit out of permission check could lead to root exploit (bsc#1264086). Changes for haveged: * Improvements on the linux kernel random subsystem have made move forward to socket communication within private network * Fix "stop" of service, the daemon in foreground actually see daemon(7) for the rationale. Only "simple" (default) and the help of udev, as starting services while starved of entropy * Add ppc64le support * update to 1.8 * Correct additional run-time test aligment problems on mips. * haveged 1.7a * Correct VPATH issues and modify check target to support parallel builds and changes in automake 1.13 test harness. * Remove all sysvinit compatibility. * fix powerpc detection

References

* bsc#1264086

Cross-

* CVE-2026-41054

CVSS scores:

* CVE-2026-41054 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Affected Products:

* Basesystem Module 15-SP7

* openSUSE Leap 15.6

* SUSE Linux Enterprise Desktop 15 SP7

* SUSE Linux Enterprise Real Time 15 SP7

* SUSE Linux Enterprise Server 15 SP6

* SUSE Linux Enterprise Server 15 SP6 LTSS

* SUSE Linux Enterprise Server 15 SP7

* SUSE Linux Enterprise Server for SAP Applications 15 SP6

* SUSE Linux Enterprise Server for SAP Applications 15 SP7

An update that solves one vulnerability can now be installed.

##

* https://www.suse.com/security/cve/CVE-2026-41054.html

* https://bugzilla.suse.com/show_bug.cgi?id=1264086

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2026:2009-1
Release Date: 2026-05-19T11:55:29Z
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here