{"id":"AZL-87113","summary":"CVE-2026-41054 affecting package haveged for versions less than 1.9.22-1","details":"In `src/havegecmd.c`, the `socket_handler` function performs a credential check on the abstract UNIX socket (`\\0/sys/entropy/haveged`). However, while it detects if the connecting user is not root (`cred.uid != 0`) and prepares a negative acknowledgement (`ASCII_NAK`), it **fails to stop execution**. The code proceeds to the `switch` statement, allowing any local unprivileged user to execute privileged commands such as `MAGIC_CHROOT`.","modified":"2026-08-28T17:47:37.230802980Z","published":"2026-05-20T10:16:26Z","upstream":["CVE-2026-41054"],"references":[{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-41054"}],"affected":[{"package":{"name":"haveged","ecosystem":"Azure Linux:3","purl":"pkg:rpm/azure-linux/haveged"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.9.22-1"}]}],"database_specific":{"source":"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-87113.json"}}],"schema_version":"1.9.0"}