PatchDay Alert

CVE

CVE-2026-41054

0field notes · 1digest CVSS 7.8


Daily digests

The haveged daemon checks whether a connecting user on its UNIX socket is root, but if the check fails it doesn't actually stop processing the request. Any local unprivileged user can send privileged commands (like MAGIC_CHROOT) to the haveged socket and have them executed. This is a classic "check but don't enforce" bug.

Get the digest

Free. Weekday mornings. Plain English CVE triage.

Check your inbox to confirm.