Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 507
Alerts This Week
Warning Icon 1 507

Stay Secure with the Latest Linux Advisories

Filter%20icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found 0 articles for you...
203

Mageia 10 Haveged Important Privilege Escalation CVE-2026-41054

Security update. Publication date: 20 Jul 2026 URL: https://advisories.mageia.org/MGASA-2026-0275.html Type: security Affected Mageia releases: 10, 9 CVE: CVE-2026-41054 Description: The updated package fixes a security vulnerability: Privilege escalation via command socket. (CVE-2026-41054) References: - https://bugs.mageia.org/show_bug.cgi?id=35550 - https://www.openwall.com/lists/oss-security/2026/05/19/3 - https://www.cve.org/CVERecord?id=CVE-2026-41054 SRPMS: - 10/core/haveged-1.9.21-2.mga10 - 9/core/haveged-1.9.21-2.mga9 . Mageia security update addresses privilege escalation in haveged package, identified as CVE-2026-41054, for Mageia 9 and 10.. Mageia security update, privilege escalation, haveged patch. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Jul 20, 2026 Important Mageia
89

Fedora 44 Haveged Important Privilege Escalation Fix 2026-02b08daa05

Update to 1.9.22 — fix systemd sandboxing: add ReadWritePaths=/dev/shm for semaphore creation Backport fix for CVE-2026-41054: privilege escalation via command socket. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-02b08daa05 2026-06-08 01:23:19.405839+00:00 -------------------------------------------------------------------------------- Name : haveged Product : Fedora 44 Version : 1.9.22 Release : 1.fc44 URL : https://github.com/jirka-h/haveged Summary : A Linux entropy source using the HAVEGE algorithm Description : A Linux entropy source using the HAVEGE algorithm Haveged is a user space entropy daemon which is not dependent upon the standard mechanisms for harvesting randomness for the system entropy pool. This is important in systems with high entropy needs or limited user interaction (e.g. headless servers). Haveged uses HAVEGE (HArdware Volatile Entropy Gathering and Expansion) to maintain a 1M pool of random bytes used to fill /dev/random whenever the supply of random bits in /dev/random falls below the low water mark of the device. The principle inputs to haveged are the sizes of the processor instruction and data caches used to setup the HAVEGE collector. The haveged default is a 4kb data cache and a 16kb instruction cache. On machines with a cpuid instruction, haveged will attempt to select appropriate values from internal tables. -------------------------------------------------------------------------------- Update Information: Update to 1.9.22 — fix systemd sandboxing: add ReadWritePaths=/dev/shm for semaphore creation Backport fix for CVE-2026-41054: privilege escalation via command socket -------------------------------------------------------------------------------- ChangeLog: * Thu May 21 2026 Jirka Hladky - 1.9.22-1 - Update to 1.9.22 - Fix systemd sandboxing: add ReadWritePaths=/dev/shm for semaphorecreation -------------------------------------------------------------------------------- References: [ 1 ] Bug #2480051 - CVE-2026-41054 haveged: privilege escalation via command socket https://bugzilla.redhat.com/show_bug.cgi?id=2480051 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-02b08daa05' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- . Patch for Fedora 44 addresses important security issue in haveged, mitigating privilege escalation risk and enhancing sandboxing.. Fedora Update, haveged Security, privilege escalation, systemd sandboxing. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Jun 08, 2026 Important Fedora
89

Fedora 44 haveged Critical Privilege Escalation CVE-2026-41054 Fix

Update to 1.9.22 — fix systemd sandboxing: add ReadWritePaths=/dev/shm for semaphore creation Backport fix for CVE-2026-41054: privilege escalation via command socket. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-02b08daa05 2026-06-08 01:23:19.405839+00:00 -------------------------------------------------------------------------------- Name : haveged Product : Fedora 44 Version : 1.9.22 Release : 1.fc44 URL : https://github.com/jirka-h/haveged Summary : A Linux entropy source using the HAVEGE algorithm Description : A Linux entropy source using the HAVEGE algorithm Haveged is a user space entropy daemon which is not dependent upon the standard mechanisms for harvesting randomness for the system entropy pool. This is important in systems with high entropy needs or limited user interaction (e.g. headless servers). Haveged uses HAVEGE (HArdware Volatile Entropy Gathering and Expansion) to maintain a 1M pool of random bytes used to fill /dev/random whenever the supply of random bits in /dev/random falls below the low water mark of the device. The principle inputs to haveged are the sizes of the processor instruction and data caches used to setup the HAVEGE collector. The haveged default is a 4kb data cache and a 16kb instruction cache. On machines with a cpuid instruction, haveged will attempt to select appropriate values from internal tables. -------------------------------------------------------------------------------- Update Information: Update to 1.9.22 — fix systemd sandboxing: add ReadWritePaths=/dev/shm for semaphore creation Backport fix for CVE-2026-41054: privilege escalation via command socket -------------------------------------------------------------------------------- ChangeLog: * Thu May 21 2026 Jirka Hladky - 1.9.22-1 - Update to 1.9.22 - Fix systemd sandboxing: add ReadWritePaths=/dev/shm for semaphorecreation -------------------------------------------------------------------------------- References: [ 1 ] Bug #2480051 - CVE-2026-41054 haveged: privilege escalation via command socket https://bugzilla.redhat.com/show_bug.cgi?id=2480051 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-02b08daa05' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- . Update for Fedora 44 addresses CVE-2026-41054 in haveged with critical severity due to privilege escalation risk.. Fedora Update, haveged, privilege escalation, systemd, Linux Security. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Jun 07, 2026 Critical Fedora
197

Debian 11 haveged Critical Local Privilege Escalation Vuln DLA-4616-1

Dirk Mueller discovered that a flaw in the function performing a credential check on the command socket of haveged, a userspace entropy daemon, may result in local privilege escalation. For Debian 11 bullseye, this problem has been fixed in version 1.9.14-1+deb11u1.. Debian LTS Advisory DLA-4616-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/lts/security/ Thorsten Alteholz June 05, 2026 https://wiki.debian.org/LTS Package : haveged Version : 1.9.14-1+deb11u1 CVE ID : CVE-2026-41054 Dirk Mueller discovered that a flaw in the function performing a credential check on the command socket of haveged, a userspace entropy daemon, may result in local privilege escalation. For Debian 11 bullseye, this problem has been fixed in version 1.9.14-1+deb11u1. We recommend that you upgrade your haveged packages. For the detailed security status of haveged please refer to its security tracker page at: https://security-tracker.debian.org/tracker/haveged Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . Local privilege escalation flaw in haveged for Debian 11 fixed in security update DLA-4616-1.. Debian Security, Linux Updates, Privilege Escalation, haveged Issues. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Jun 05, 2026 Critical Debian LTS
197

Debian LTS haveged Critical Local Privilege Escalation DLA-4616-1

Dirk Mueller discovered that a flaw in the function performing a credential check on the command socket of haveged, a userspace entropy daemon, may result in local privilege escalation. For Debian 11 bullseye, this problem has been fixed in version 1.9.14-1+deb11u1.. Debian LTS Advisory DLA-4616-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/lts/security/ Thorsten Alteholz June 05, 2026 https://wiki.debian.org/LTS Package : haveged Version : 1.9.14-1+deb11u1 CVE ID : CVE-2026-41054 Dirk Mueller discovered that a flaw in the function performing a credential check on the command socket of haveged, a userspace entropy daemon, may result in local privilege escalation. For Debian 11 bullseye, this problem has been fixed in version 1.9.14-1+deb11u1. We recommend that you upgrade your haveged packages. For the detailed security status of haveged please refer to its security tracker page at: https://security-tracker.debian.org/tracker/haveged Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . A critical security update for haveged in Debian LTS addresses a local privilege escalation risk. Upgrade recommended.. Debian LTS, haveged, security update, local privilege escalation, critical patch. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Jun 05, 2026 Critical Debian LTS
172

Ubuntu 26.04 LTS haveged Critical Exec Privilege Escalation USN-8358-1

haveged could be made to run programs as an administrator.. ========================================================================== Ubuntu Security Notice USN-8358-1 June 01, 2026 haveged vulnerability ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 26.04 LTS - Ubuntu 25.10 - Ubuntu 24.04 LTS - Ubuntu 22.04 LTS Summary: haveged could be made to run programs as an administrator. Software Description: - haveged: userspace entropy daemon Details: It was discovered that haveged incorrectly handled credential checks on its control socket. A local attacker could possibly use this issue to execute privileged commands. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 26.04 LTS haveged 1.9.19-14ubuntu0.1 libhavege2 1.9.19-14ubuntu0.1 Ubuntu 25.10 haveged 1.9.19-12+deb13u1build0.25.10.1 libhavege2 1.9.19-12+deb13u1build0.25.10.1 Ubuntu 24.04 LTS haveged 1.9.14-1ubuntu2+esm1~24.04.1 Available with Ubuntu Pro libhavege2 1.9.14-1ubuntu2+esm1~24.04.1 Available with Ubuntu Pro Ubuntu 22.04 LTS haveged 1.9.14-1ubuntu1+esm1~22.04.1 Available with Ubuntu Pro libhavege2 1.9.14-1ubuntu1+esm1~22.04.1 Available with Ubuntu Pro After a standard system update you need to restart haveged to make all the necessary changes. References: https://ubuntu.com/security/notices/USN-8358-1 CVE-2026-41054 Package Information: https://launchpad.net/ubuntu/+source/haveged/1.9.19-14ubuntu0.1 https://launchpad.net/ubuntu/+source/haveged/1.9.19-12+deb13u1build0.25.10.1 . A critical security issue in haveged for Ubuntuallows local attackers to run commands as administrators.. Ubuntu Security Notice, haveged vulnerability, privilege escalation. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Jun 01, 2026 Critical Ubuntu
172

Ubuntu 26.04 LTS haveged Important Local Attack Escalation CVE-2026-41054

haveged could be made to run programs as an administrator.. ========================================================================== Ubuntu Security Notice USN-8358-1 June 01, 2026 haveged vulnerability ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 26.04 LTS - Ubuntu 25.10 - Ubuntu 24.04 LTS - Ubuntu 22.04 LTS Summary: haveged could be made to run programs as an administrator. Software Description: - haveged: userspace entropy daemon Details: It was discovered that haveged incorrectly handled credential checks on its control socket. A local attacker could possibly use this issue to execute privileged commands. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 26.04 LTS haveged 1.9.19-14ubuntu0.1 libhavege2 1.9.19-14ubuntu0.1 Ubuntu 25.10 haveged 1.9.19-12+deb13u1build0.25.10.1 libhavege2 1.9.19-12+deb13u1build0.25.10.1 Ubuntu 24.04 LTS haveged 1.9.14-1ubuntu2+esm1~24.04.1 Available with Ubuntu Pro libhavege2 1.9.14-1ubuntu2+esm1~24.04.1 Available with Ubuntu Pro Ubuntu 22.04 LTS haveged 1.9.14-1ubuntu1+esm1~22.04.1 Available with Ubuntu Pro libhavege2 1.9.14-1ubuntu1+esm1~22.04.1 Available with Ubuntu Pro After a standard system update you need to restart haveged to make all the necessary changes. References: https://ubuntu.com/security/notices/USN-8358-1 CVE-2026-41054 Package Information: https://launchpad.net/ubuntu/+source/haveged/1.9.19-14ubuntu0.1 https://launchpad.net/ubuntu/+source/haveged/1.9.19-12+deb13u1build0.25.10.1 . Update your Ubuntu installation to address criticalhaveged issue allowing local privilege escalation. Read more for details.. Ubuntu security, haveged vulnerability, local privilege escalation, Ubuntu update instructions. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Jun 01, 2026 Important Ubuntu
87

Debian Bookworm haveged Important Local Privilege Escalation Fix DSA-6292-1

Dirk Mueller discovered that a flaw in the function performing a credential check on the command socket of haveged, a userspace entropy daemon, may result in local privilege escalation. For the oldstable distribution (bookworm), this problem has been fixed in version 1.9.14-1+deb12u1.. - ------------------------------------------------------------------------- Debian Security Advisory DSA-6292-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/security/ Salvatore Bonaccorso May 22, 2026 https://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : haveged CVE ID : CVE-2026-41054 Debian Bug : 1137096 Dirk Mueller discovered that a flaw in the function performing a credential check on the command socket of haveged, a userspace entropy daemon, may result in local privilege escalation. For the oldstable distribution (bookworm), this problem has been fixed in version 1.9.14-1+deb12u1. For the stable distribution (trixie), this problem has been fixed in version 1.9.19-12+deb13u1. We recommend that you upgrade your haveged packages. For the detailed security status of haveged please refer to its security tracker page at: https://security-tracker.debian.org/tracker/haveged Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . A flaw in haveged allows local privilege escalation. Fixed in version 1.9.14-1+deb12u1 for Debian Bookworm.. Debian Security Advisory, Haveged, Local Privilege Escalation, Debian Update. . Severity: Important. LinuxSecurity.com Team

Calendar%202 May 22, 2026 Important Debian
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200