## This update for haveged fixes the following issue * CVE-2026-41054: missing exit out of permission check could lead to root exploit (bsc#1264086). Changes for haveged: * Improvements on the linux kernel random subsystem have made move forward to socket communication within private network * Fix "stop" of service, the daemon in foreground actually see daemon(7) for the rationale. Only "simple" (default) and the help of udev, as starting services while starved of entropy * Add ppc64le support * update to 1.8 * Correct additional run-time test aligment problems on mips. * haveged 1.7a * Correct VPATH issues and modify check target to support parallel builds and changes in automake 1.13 test harness. * Remove all sysvinit compatibility. * fix powerpc detection
* bsc#1264086
Cross-
* CVE-2026-41054
CVSS scores:
* CVE-2026-41054 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Affected Products:
* Basesystem Module 15-SP7
* openSUSE Leap 15.6
* SUSE Linux Enterprise Desktop 15 SP7
* SUSE Linux Enterprise Real Time 15 SP7
* SUSE Linux Enterprise Server 15 SP6
* SUSE Linux Enterprise Server 15 SP6 LTSS
* SUSE Linux Enterprise Server 15 SP7
* SUSE Linux Enterprise Server for SAP Applications 15 SP6
* SUSE Linux Enterprise Server for SAP Applications 15 SP7
An update that solves one vulnerability can now be installed.
##
* https://www.suse.com/security/cve/CVE-2026-41054.html
* https://bugzilla.suse.com/show_bug.cgi?id=1264086
Get the latest Linux and open source security news straight to your inbox.