UbuntuUpdates.org

Package "libhavege2"

Name: libhavege2

Description:

entropy source using the HAVEGE algorithm - shared library

Latest version: 1.9.19-14ubuntu0.1
Release: resolute (26.04)
Level: security
Repository: universe
Head package: haveged
Homepage: https://issihosts.com/haveged/

Links


Download "libhavege2"


Other versions of "libhavege2" in Resolute

Repository Area Version
base universe 1.9.19-14
updates universe 1.9.19-14ubuntu0.1

Changelog

Version: 1.9.19-14ubuntu0.1 2026-06-01 18:08:06 UTC

  haveged (1.9.19-14ubuntu0.1) resolute-security; urgency=medium

  * SECURITY UPDATE: Privilege escalation
    - debian/patches/Fix-privilege-escalation-via-command-socket-CVE-2026.patch:
      Fix privilege escalation via command socket (CVE-2026-41054)
    - debian/patches/Check-peer-credentials-before-reading-command-CVE-20.patch:
      Check peer credentials before reading command (CVE-2026-41054)
    - CVE-2026-41054

 -- John Breton <email address hidden> Thu, 28 May 2026 21:57:18 -0400

CVE-2026-41054 In `src/havegecmd.c`, the `socket_handler` function performs a credential check on the abstract UNIX socket (`\0/sys/entropy/haveged`). However, whil



About   -   Send Feedback to @ubuntu_updates