authd could be made to escalate privileges.. ========================================================================== Ubuntu Security Notice USN-8212-1 April 27, 2026 authd vulnerability ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: Summary: authd could be made to escalate privileges. Software Description: Details: It was discovered that authd incorrectly assigned the primary group ID to users under certain conditions. A local attacker could possibly use this issue to achieve privilege escalation, or gain unauthorized access to files belonging to other users. Update instructions: The problem can be corrected by updating your system to the following package versions: After a standard system update you need to restart authd to make all the necessary changes. References: https://ubuntu.com/security/notices/USN-8212-1 CVE-2026-6970 . An important advisory for Ubuntu users regarding an authd issue that could lead to privilege escalation for local attackers.. Ubuntu authd privilege escalation announcement update. . Severity: Important. LinuxSecurity.com Team
fix double-free prob detected on x86_64 glibc (#136392). --------------------------------------------------------------------- Fedora Update Notification FEDORA-2004-419 2004-11-16 --------------------------------------------------------------------- Product : Fedora Core 3 Name : authd Version : 1.4.3 Release : 1 Summary : a RFC 1413 ident protocol daemon Description : authd is a small and fast RFC 1413 ident protocol daemon with both xinetd server and interactive modes that supports IPv6 and IPv4 as well as the more popular features of pidentd. --------------------------------------------------------------------- Update Information: Version 1.4.3 of authd fixes a segfault seen on x86_64 arches due to a double free. --------------------------------------------------------------------- * Tue Nov 16 2004 Adrian Havill - 1.4.3-1 - fix double-free prob detected on x86_64 glibc (#136392) --------------------------------------------------------------------- This update can be downloaded from: 354a3dd252f3830414fb3cfd462e4c91 SRPMS/authd-1.4.3-1.src.rpm d751b6f25f8d477c00d9fece7537b259 x86_64/authd-1.4.3-1.x86_64.rpm a5d0e57dda182ff61c67e49f2c0bd05c x86_64/debug/authd-debuginfo-1.4.3-1.x86_64.rpm 9e70ce3e5bada1d25fa539d78b4d8949 i386/authd-1.4.3-1.i386.rpm 510ca456ea479853ec47f8aea2560cd3 i386/debug/authd-debuginfo-1.4.3-1.i386.rpm This update can also be installed with the Update Agent; you can launch the Update Agent with the 'up2date' command. --------------------------------------------------------------------- -- fedora-announce-list mailing list
Get the latest Linux and open source security news straight to your inbox.