In `src/havegecmd.c`, the `socket_handler` function performs a credential check on the abstract UNIX socket (`\0/sys/entropy/haveged`). However, while it detects if the connecting user is not root (`cred.uid != 0`) and prepares a negative acknowledgement (`ASCII_NAK`), it **fails to stop execution**. The code proceeds to the `switch` statement, allowing any local unprivileged user to execute privileged commands such as `MAGIC_CHROOT`.
CVSS Details
- CVSS 3.1 Base Score: 7.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade haveged | May 25, 2026 | May 20, 2026 |
| Debian | — | Upgrade haveged | May 24, 2026 | May 24, 2026 |
| Gentoo Linux | — | Upgrade sys-apps/haveged. | Aug 16, 2026 | Aug 15, 2026 |
| Ubuntu | — | Upgrade libhavege2 (Ubuntu Pro)Upgrade havegedUpgrade libhavege2Upgrade haveged (Ubuntu Pro) | Jun 2, 2026 | Jun 1, 2026 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub