{"dataType": "CVE_RECORD", "dataVersion": "5.2", "cveMetadata": {"cveId": "CVE-2026-41054", "assignerOrgId": "404e59f5-483d-4b8a-8e7a-e67604dd8afb", "state": "PUBLISHED", "assignerShortName": "suse", "dateReserved": "2026-04-16T13:37:50.680Z", "datePublished": "2026-05-20T08:56:14.466Z", "dateUpdated": "2026-05-20T12:18:15.866Z"}, "containers": {"cna": {"providerMetadata": {"orgId": "404e59f5-483d-4b8a-8e7a-e67604dd8afb", "shortName": "suse", "dateUpdated": "2026-05-20T08:56:14.466Z"}, "title": "Missing exit out of permission check in haveged could lead to root exploit", "problemTypes": [{"descriptions": [{"lang": "en", "cweId": "CWE-305", "description": "CWE-305: Authentication Bypass by Primary Weakness", "type": "CWE"}]}], "affected": [{"vendor": "SUSE", "product": "Container suse/sle-micro-rancher/5.3:latest", "packageName": "haveged", "versions": [{"status": "affected", "version": "?", "lessThan": "1.9.14-150400.3.11.1", "versionType": "custom"}], "defaultStatus": "unaffected"}, {"vendor": "SUSE", "product": "Container suse/sle-micro-rancher/5.3:latest", "packageName": "libhavege2", "versions": [{"status": "affected", "version": "?", "lessThan": "1.9.14-150400.3.11.1", "versionType": "custom"}], "defaultStatus": "unaffected"}, {"vendor": "SUSE", "product": "Container suse/sle-micro-rancher/5.4:latest", "packageName": "haveged", "versions": [{"status": "affected", "version": "?", "lessThan": "1.9.14-150400.3.11.1", "versionType": "custom"}], "defaultStatus": "unaffected"}, {"vendor": "SUSE", "product": "Container suse/sle-micro-rancher/5.4:latest", "packageName": "libhavege2", "versions": [{"status": "affected", "version": "?", "lessThan": "1.9.14-150400.3.11.1", "versionType": "custom"}], "defaultStatus": "unaffected"}, {"vendor": "SUSE", "product": "Container suse/sle-micro/5.5:latest", "packageName": "haveged", "versions": [{"status": "affected", "version": "?", "lessThan": "1.9.14-150400.3.11.1", "versionType": "custom"}], "defaultStatus": "unaffected"}, {"vendor": "SUSE", "product": "Container suse/sle-micro/5.5:latest", "packageName": "libhavege2", "versions": [{"status": "affected", "version": "?", "lessThan": "1.9.14-150400.3.11.1", "versionType": "custom"}], "defaultStatus": "unaffected"}, {"vendor": "SUSE", "product": "Image SLES15-SP4-SAP-BYOS", "packageName": "haveged", "versions": [{"status": "affected", "version": "?", "lessThan": "1.9.14-150400.3.11.1", "versionType": "custom"}], "defaultStatus": "unaffected"}, {"vendor": "SUSE", "product": "Image SLES15-SP4-SAP-BYOS", "packageName": "libhavege2", "versions": [{"status": "affected", "version": "?", "lessThan": "1.9.14-150400.3.11.1", "versionType": "custom"}], "defaultStatus": "unaffected"}, {"vendor": "SUSE", "product": "Image SLES15-SP4-SAP-BYOS-Azure", "packageName": "haveged", "versions": [{"status": "affected", "version": "?", "lessThan": "1.9.14-150400.3.11.1", "versionType": "custom"}], "defaultStatus": "unaffected"}, {"vendor": "SUSE", "product": "Image SLES15-SP4-SAP-BYOS-Azure", "packageName": "libhavege2", "versions": [{"status": "affected", "version": "?", "lessThan": "1.9.14-150400.3.11.1", "versionType": "custom"}], "defaultStatus": "unaffected"}, {"vendor": "SUSE", "product": "Image SLES15-SP4-SAP-BYOS-EC2", "packageName": "haveged", "versions": [{"status": "affected", "version": "?", "lessThan": "1.9.14-150400.3.11.1", "versionType": "custom"}], "defaultStatus": "unaffected"}, {"vendor": "SUSE", "product": "Image SLES15-SP4-SAP-BYOS-EC2", "packageName": "libhavege2", "versions": [{"status": "affected", "version": "?", "lessThan": "1.9.14-150400.3.11.1", "versionType": "custom"}], "defaultStatus": "unaffected"}, {"vendor": "SUSE", "product": "Image SLES15-SP4-SAP-BYOS-GCE", "packageName": "haveged", "versions": [{"status": "affected", "version": "?", "lessThan": "1.9.14-150400.3.11.1", "versionType": "custom"}], "defaultStatus": "unaffected"}, {"vendor": "SUSE", "product": "Image SLES15-SP4-SAP-BYOS-GCE", "packageName": "libhavege2", "versions": [{"status": "affected", "version": "?", "lessThan": "1.9.14-150400.3.11.1", "versionType": "custom"}], "defaultStatus": "unaffected"}, {"vendor": "SUSE", "product": "Image SLES15-SP4-SAP-Hardened", "packageName": "haveged", "versions": [{"status": "affected", "version": "?", "lessThan": "1.9.14-150400.3.11.1", "versionType": "custom"}], "defaultStatus": "unaffected"}, {"vendor": "SUSE", "product": "Image SLES15-SP4-SAP-Hardened", "packageName": "libhavege2", "versions": [{"status": "affected", "version": "?", "lessThan": "1.9.14-150400.3.11.1", "versionType": "custom"}], "defaultStatus": "unaffected"}, {"vendor": "SUSE", "product": "Image SLES15-SP4-SAP-Hardened-BYOS", "packageName": "haveged", "versions": [{"status": "affected", "version": "?", "lessThan": "1.9.14-150400.3.11.1", "versionType": "custom"}], "defaultStatus": "unaffected"}, {"vendor": "SUSE", "product": "Image SLES15-SP4-SAP-Hardened-BYOS", "packageName": "libhavege2", "versions": [{"status": "affected", "version": "?", "lessThan": "1.9.14-150400.3.11.1", "versionType": "custom"}], "defaultStatus": "unaffected"}, {"vendor": "SUSE", "product": "Image SLES15-SP4-SAP-Hardened-BYOS-Azure", "packageName": "haveged", "versions": [{"status": "affected", "version": "?", "lessThan": "1.9.14-150400.3.11.1", "versionType": "custom"}], "defaultStatus": "unaffected"}, {"vendor": "SUSE", "product": "Image SLES15-SP4-SAP-Hardened-BYOS-Azure", "packageName": "libhavege2", "versions": [{"status": "affected", "version": "?", "lessThan": "1.9.14-150400.3.11.1", "versionType": "custom"}], "defaultStatus": "unaffected"}, {"vendor": "SUSE", "product": "Image SLES15-SP4-SAP-Hardened-BYOS-EC2", "packageName": "haveged", "versions": [{"status": "affected", "version": "?", "lessThan": "1.9.14-150400.3.11.1", "versionType": "custom"}], "defaultStatus": "unaffected"}, {"vendor": "SUSE", "product": "Image SLES15-SP4-SAP-Hardened-BYOS-EC2", "packageName": "libhavege2", "versions": [{"status": "affected", "version": "?", "lessThan": "1.9.14-150400.3.11.1", "versionType": "custom"}], "defaultStatus": "unaffected"}, {"vendor": "SUSE", "product": "Image SLES15-SP4-SAP-Hardened-BYOS-GCE", "packageName": "haveged", "versions": [{"status": "affected", "version": "?", "lessThan": "1.9.14-150400.3.11.1", "versionType": "custom"}], "defaultStatus": "unaffected"}, {"vendor": "SUSE", "product": "Image SLES15-SP4-SAP-Hardened-BYOS-GCE", "packageName": "libhavege2", "versions": [{"status": "affected", "version": "?", "lessThan": "1.9.14-150400.3.11.1", "versionType": "custom"}], "defaultStatus": "unaffected"}, {"vendor": "SUSE", "product": "Image SLES15-SP4-SAP-Hardened-GCE", "packageName": "haveged", "versions": [{"status": "affected", "version": "?", "lessThan": "1.9.14-150400.3.11.1", "versionType": "custom"}], "defaultStatus": "unaffected"}, {"vendor": "SUSE", "product": "Image SLES15-SP4-SAP-Hardened-GCE", "packageName": "libhavege2", "versions": [{"status": "affected", "version": "?", "lessThan": "1.9.14-150400.3.11.1", "versionType": "custom"}], "defaultStatus": "unaffected"}, {"vendor": "SUSE", "product": "SUSE Linux Enterprise Desktop 15 SP7", "packageName": "haveged", "versions": [{"status": "affected", "version": "?", "lessThan": "1.9.14-150600.11.6.1", "versionType": "custom"}], "defaultStatus": "unaffected"}, {"vendor": "SUSE", "product": "SUSE Linux Enterprise Desktop 15 SP7", "packageName": "haveged-devel", "versions": [{"status": "affected", "version": "?", "lessThan": "1.9.14-150600.11.6.1", "versionType": "custom"}], "defaultStatus": "unaffected"}, {"vendor": "SUSE", "product": "SUSE Linux Enterprise Desktop 15 SP7", "packageName": "libhavege2", "versions": [{"status": "affected", "version": "?", "lessThan": "1.9.14-150600.11.6.1", "versionType": "custom"}], "defaultStatus": "unaffected"}, {"vendor": "SUSE", "product": "SUSE Linux Enterprise High Performance Computing 15 SP7", "packageName": "haveged", "versions": [{"status": "affected", "version": "?", "lessThan": "1.9.14-150600.11.6.1", "versionType": "custom"}], "defaultStatus": "unaffected"}, {"vendor": "SUSE", "product": "SUSE Linux Enterprise High Performance Computing 15 SP7", "packageName": "haveged-devel", "versions": [{"status": "affected", "version": "?", "lessThan": "1.9.14-150600.11.6.1", "versionType": "custom"}], "defaultStatus": "unaffected"}, {"vendor": "SUSE", "product": "SUSE Linux Enterprise High Performance Computing 15 SP7", "packageName": "libhavege2", "versions": [{"status": "affected", "version": "?", "lessThan": "1.9.14-150600.11.6.1", "versionType": "custom"}], "defaultStatus": "unaffected"}, {"vendor": "SUSE", "product": "SUSE Linux Enterprise Module for Basesystem 15 SP7", "packageName": "haveged", "versions": [{"status": "affected", "version": "?", "lessThan": "1.9.14-150600.11.6.1", "versionType": "custom"}], "defaultStatus": "unaffected"}, {"vendor": "SUSE", "product": "SUSE Linux Enterprise Module for Basesystem 15 SP7", "packageName": "haveged-devel", "versions": [{"status": "affected", "version": "?", "lessThan": "1.9.14-150600.11.6.1", "versionType": "custom"}], "defaultStatus": "unaffected"}, {"vendor": "SUSE", "product": "SUSE Linux Enterprise Module for Basesystem 15 SP7", "packageName": "libhavege2", "versions": [{"status": "affected", "version": "?", "lessThan": "1.9.14-150600.11.6.1", "versionType": "custom"}], "defaultStatus": "unaffected"}, {"vendor": "SUSE", "product": "SUSE Linux Enterprise Server 15 SP7", "packageName": "haveged", "versions": [{"status": "affected", "version": "?", "lessThan": "1.9.14-150600.11.6.1", "versionType": "custom"}], "defaultStatus": "unaffected"}, {"vendor": "SUSE", "product": "SUSE Linux Enterprise Server 15 SP7", "packageName": "haveged-devel", "versions": [{"status": "affected", "version": "?", "lessThan": "1.9.14-150600.11.6.1", "versionType": "custom"}], "defaultStatus": "unaffected"}, {"vendor": "SUSE", "product": "SUSE Linux Enterprise Server 15 SP7", "packageName": "libhavege2", "versions": [{"status": "affected", "version": "?", "lessThan": "1.9.14-150600.11.6.1", "versionType": "custom"}], "defaultStatus": "unaffected"}, {"vendor": "SUSE", "product": "SUSE Linux Enterprise Server for SAP Applications 15 SP7", "packageName": "haveged", "versions": [{"status": "affected", "version": "?", "lessThan": "1.9.14-150600.11.6.1", "versionType": "custom"}], "defaultStatus": "unaffected"}, {"vendor": "SUSE", "product": "SUSE Linux Enterprise Server for SAP Applications 15 SP7", "packageName": "haveged-devel", "versions": [{"status": "affected", "version": "?", "lessThan": "1.9.14-150600.11.6.1", "versionType": "custom"}], "defaultStatus": "unaffected"}, {"vendor": "SUSE", "product": "SUSE Linux Enterprise Server for SAP Applications 15 SP7", "packageName": "libhavege2", "versions": [{"status": "affected", "version": "?", "lessThan": "1.9.14-150600.11.6.1", "versionType": "custom"}], "defaultStatus": "unaffected"}, {"vendor": "SUSE", "product": "SUSE Linux Enterprise High Performance Computing 15 SP4-ESPOS", "packageName": "haveged", "versions": [{"status": "affected", "version": "?", "lessThan": "1.9.14-150400.3.11.1", "versionType": "custom"}], "defaultStatus": "unaffected"}, {"vendor": "SUSE", "product": "SUSE Linux Enterprise High Performance Computing 15 SP4-ESPOS", "packageName": "haveged-devel", "versions": [{"status": "affected", "version": "?", "lessThan": "1.9.14-150400.3.11.1", "versionType": "custom"}], "defaultStatus": "unaffected"}, {"vendor": "SUSE", "product": "SUSE Linux Enterprise High Performance Computing 15 SP4-ESPOS", "packageName": "libhavege2", "versions": [{"status": "affected", "version": "?", "lessThan": "1.9.14-150400.3.11.1", "versionType": "custom"}], "defaultStatus": "unaffected"}, {"vendor": "SUSE", "product": "SUSE Linux Enterprise High Performance Computing 15 SP4-LTSS", "packageName": "haveged", "versions": [{"status": "affected", "version": "?", "lessThan": "1.9.14-150400.3.11.1", "versionType": "custom"}], "defaultStatus": "unaffected"}, {"vendor": "SUSE", "product": "SUSE Linux Enterprise High Performance Computing 15 SP4-LTSS", "packageName": "haveged-devel", "versions": [{"status": "affected", "version": "?", "lessThan": "1.9.14-150400.3.11.1", "versionType": "custom"}], "defaultStatus": "unaffected"}, {"vendor": "SUSE", "product": "SUSE Linux Enterprise High Performance Computing 15 SP4-LTSS", "packageName": "libhavege2", "versions": [{"status": "affected", "version": "?", "lessThan": "1.9.14-150400.3.11.1", "versionType": "custom"}], "defaultStatus": "unaffected"}, {"vendor": "SUSE", "product": "SUSE Linux Enterprise High Performance Computing 15 SP5-ESPOS", "packageName": "haveged", "versions": [{"status": "affected", "version": "?", "lessThan": "1.9.14-150400.3.11.1", "versionType": "custom"}], "defaultStatus": "unaffected"}, {"vendor": "SUSE", "product": "SUSE Linux Enterprise High Performance Computing 15 SP5-ESPOS", "packageName": "haveged-devel", "versions": [{"status": "affected", "version": "?", "lessThan": "1.9.14-150400.3.11.1", "versionType": "custom"}], "defaultStatus": "unaffected"}, {"vendor": "SUSE", "product": "SUSE Linux Enterprise High Performance Computing 15 SP5-ESPOS", "packageName": "libhavege2", "versions": [{"status": "affected", "version": "?", "lessThan": "1.9.14-150400.3.11.1", "versionType": "custom"}], "defaultStatus": "unaffected"}, {"vendor": "SUSE", "product": "SUSE Linux Enterprise High Performance Computing 15 SP5-LTSS", "packageName": "haveged", "versions": [{"status": "affected", "version": "?", "lessThan": "1.9.14-150400.3.11.1", "versionType": "custom"}], "defaultStatus": "unaffected"}, {"vendor": "SUSE", "product": "SUSE Linux Enterprise High Performance Computing 15 SP5-LTSS", "packageName": "haveged-devel", "versions": [{"status": "affected", "version": "?", "lessThan": "1.9.14-150400.3.11.1", "versionType": "custom"}], "defaultStatus": "unaffected"}, {"vendor": "SUSE", "product": "SUSE Linux Enterprise High Performance Computing 15 SP5-LTSS", "packageName": "libhavege2", "versions": [{"status": "affected", "version": "?", "lessThan": "1.9.14-150400.3.11.1", "versionType": "custom"}], "defaultStatus": "unaffected"}, {"vendor": "SUSE", "product": "SUSE Linux Enterprise Micro 5.3", "packageName": "haveged", "versions": [{"status": "affected", "version": "?", "lessThan": "1.9.14-150400.3.11.1", "versionType": "custom"}], "defaultStatus": "unaffected"}, {"vendor": "SUSE", "product": "SUSE Linux Enterprise Micro 5.3", "packageName": "libhavege2", "versions": [{"status": "affected", "version": "?", "lessThan": "1.9.14-150400.3.11.1", "versionType": "custom"}], "defaultStatus": "unaffected"}, {"vendor": "SUSE", "product": "SUSE Linux Enterprise Micro 5.4", "packageName": "haveged", "versions": [{"status": "affected", "version": "?", "lessThan": "1.9.14-150400.3.11.1", "versionType": "custom"}], "defaultStatus": "unaffected"}, {"vendor": "SUSE", "product": "SUSE Linux Enterprise Micro 5.4", "packageName": "libhavege2", "versions": [{"status": "affected", "version": "?", "lessThan": "1.9.14-150400.3.11.1", "versionType": "custom"}], "defaultStatus": "unaffected"}, {"vendor": "SUSE", "product": "SUSE Linux Enterprise Micro 5.5", "packageName": "haveged", "versions": [{"status": "affected", "version": "?", "lessThan": "1.9.14-150400.3.11.1", "versionType": "custom"}], "defaultStatus": "unaffected"}, {"vendor": "SUSE", "product": "SUSE Linux Enterprise Micro 5.5", "packageName": "libhavege2", "versions": [{"status": "affected", "version": "?", "lessThan": "1.9.14-150400.3.11.1", "versionType": "custom"}], "defaultStatus": "unaffected"}, {"vendor": "SUSE", "product": "SUSE Linux Enterprise Server 15 SP4-LTSS", "packageName": "haveged", "versions": [{"status": "affected", "version": "?", "lessThan": "1.9.14-150400.3.11.1", "versionType": "custom"}], "defaultStatus": "unaffected"}, {"vendor": "SUSE", "product": "SUSE Linux Enterprise Server 15 SP4-LTSS", "packageName": "haveged-devel", "versions": [{"status": "affected", "version": "?", "lessThan": "1.9.14-150400.3.11.1", "versionType": "custom"}], "defaultStatus": "unaffected"}, {"vendor": "SUSE", "product": "SUSE Linux Enterprise Server 15 SP4-LTSS", "packageName": "libhavege2", "versions": [{"status": "affected", "version": "?", "lessThan": "1.9.14-150400.3.11.1", "versionType": "custom"}], "defaultStatus": "unaffected"}, {"vendor": "SUSE", "product": "SUSE Linux Enterprise Server 15 SP5-LTSS", "packageName": "haveged", "versions": [{"status": "affected", "version": "?", "lessThan": "1.9.14-150400.3.11.1", "versionType": "custom"}], "defaultStatus": "unaffected"}, {"vendor": "SUSE", "product": "SUSE Linux Enterprise Server 15 SP5-LTSS", "packageName": "haveged-devel", "versions": [{"status": "affected", "version": "?", "lessThan": "1.9.14-150400.3.11.1", "versionType": "custom"}], "defaultStatus": "unaffected"}, {"vendor": "SUSE", "product": "SUSE Linux Enterprise Server 15 SP5-LTSS", "packageName": "libhavege2", "versions": [{"status": "affected", "version": "?", "lessThan": "1.9.14-150400.3.11.1", "versionType": "custom"}], "defaultStatus": "unaffected"}, {"vendor": "SUSE", "product": "SUSE Linux Enterprise Server 15 SP6-LTSS", "packageName": "haveged", "versions": [{"status": "affected", "version": "?", "lessThan": "1.9.14-150600.11.6.1", "versionType": "custom"}], "defaultStatus": "unaffected"}, {"vendor": "SUSE", "product": "SUSE Linux Enterprise Server 15 SP6-LTSS", "packageName": "haveged-devel", "versions": [{"status": "affected", "version": "?", "lessThan": "1.9.14-150600.11.6.1", "versionType": "custom"}], "defaultStatus": "unaffected"}, {"vendor": "SUSE", "product": "SUSE Linux Enterprise Server 15 SP6-LTSS", "packageName": "libhavege2", "versions": [{"status": "affected", "version": "?", "lessThan": "1.9.14-150600.11.6.1", "versionType": "custom"}], "defaultStatus": "unaffected"}, {"vendor": "SUSE", "product": "SUSE Linux Enterprise Server for SAP Applications 15 SP4", "packageName": "haveged", "versions": [{"status": "affected", "version": "?", "lessThan": "1.9.14-150400.3.11.1", "versionType": "custom"}], "defaultStatus": "unaffected"}, {"vendor": "SUSE", "product": "SUSE Linux Enterprise Server for SAP Applications 15 SP4", "packageName": "haveged-devel", "versions": [{"status": "affected", "version": "?", "lessThan": "1.9.14-150400.3.11.1", "versionType": "custom"}], "defaultStatus": "unaffected"}, {"vendor": "SUSE", "product": "SUSE Linux Enterprise Server for SAP Applications 15 SP4", "packageName": "libhavege2", "versions": [{"status": "affected", "version": "?", "lessThan": "1.9.14-150400.3.11.1", "versionType": "custom"}], "defaultStatus": "unaffected"}, {"vendor": "SUSE", "product": "SUSE Linux Enterprise Server for SAP Applications 15 SP5", "packageName": "haveged", "versions": [{"status": "affected", "version": "?", "lessThan": "1.9.14-150400.3.11.1", "versionType": "custom"}], "defaultStatus": "unaffected"}, {"vendor": "SUSE", "product": "SUSE Linux Enterprise Server for SAP Applications 15 SP5", "packageName": "haveged-devel", "versions": [{"status": "affected", "version": "?", "lessThan": "1.9.14-150400.3.11.1", "versionType": "custom"}], "defaultStatus": "unaffected"}, {"vendor": "SUSE", "product": "SUSE Linux Enterprise Server for SAP Applications 15 SP5", "packageName": "libhavege2", "versions": [{"status": "affected", "version": "?", "lessThan": "1.9.14-150400.3.11.1", "versionType": "custom"}], "defaultStatus": "unaffected"}, {"vendor": "SUSE", "product": "SUSE Linux Enterprise Server for SAP Applications 15 SP6", "packageName": "haveged", "versions": [{"status": "affected", "version": "?", "lessThan": "1.9.14-150600.11.6.1", "versionType": "custom"}], "defaultStatus": "unaffected"}, {"vendor": "SUSE", "product": "SUSE Linux Enterprise Server for SAP Applications 15 SP6", "packageName": "haveged-devel", "versions": [{"status": "affected", "version": "?", "lessThan": "1.9.14-150600.11.6.1", "versionType": "custom"}], "defaultStatus": "unaffected"}, {"vendor": "SUSE", "product": "SUSE Linux Enterprise Server for SAP Applications 15 SP6", "packageName": "libhavege2", "versions": [{"status": "affected", "version": "?", "lessThan": "1.9.14-150600.11.6.1", "versionType": "custom"}], "defaultStatus": "unaffected"}, {"vendor": "SUSE", "product": "SUSE Manager Proxy LTS 4.3", "packageName": "haveged", "versions": [{"status": "affected", "version": "?", "lessThan": "1.9.14-150400.3.11.1", "versionType": "custom"}], "defaultStatus": "unaffected"}, {"vendor": "SUSE", "product": "SUSE Manager Proxy LTS 4.3", "packageName": "haveged-devel", "versions": [{"status": "affected", "version": "?", "lessThan": "1.9.14-150400.3.11.1", "versionType": "custom"}], "defaultStatus": "unaffected"}, {"vendor": "SUSE", "product": "SUSE Manager Proxy LTS 4.3", "packageName": "libhavege2", "versions": [{"status": "affected", "version": "?", "lessThan": "1.9.14-150400.3.11.1", "versionType": "custom"}], "defaultStatus": "unaffected"}, {"vendor": "SUSE", "product": "SUSE Manager Retail Branch Server LTS 4.3", "packageName": "haveged", "versions": [{"status": "affected", "version": "?", "lessThan": "1.9.14-150400.3.11.1", "versionType": "custom"}], "defaultStatus": "unaffected"}, {"vendor": "SUSE", "product": "SUSE Manager Retail Branch Server LTS 4.3", "packageName": "haveged-devel", "versions": [{"status": "affected", "version": "?", "lessThan": "1.9.14-150400.3.11.1", "versionType": "custom"}], "defaultStatus": "unaffected"}, {"vendor": "SUSE", "product": "SUSE Manager Retail Branch Server LTS 4.3", "packageName": "libhavege2", "versions": [{"status": "affected", "version": "?", "lessThan": "1.9.14-150400.3.11.1", "versionType": "custom"}], "defaultStatus": "unaffected"}, {"vendor": "SUSE", "product": "SUSE Manager Server LTS 4.3", "packageName": "haveged", "versions": [{"status": "affected", "version": "?", "lessThan": "1.9.14-150400.3.11.1", "versionType": "custom"}], "defaultStatus": "unaffected"}, {"vendor": "SUSE", "product": "SUSE Manager Server LTS 4.3", "packageName": "haveged-devel", "versions": [{"status": "affected", "version": "?", "lessThan": "1.9.14-150400.3.11.1", "versionType": "custom"}], "defaultStatus": "unaffected"}, {"vendor": "SUSE", "product": "SUSE Manager Server LTS 4.3", "packageName": "libhavege2", "versions": [{"status": "affected", "version": "?", "lessThan": "1.9.14-150400.3.11.1", "versionType": "custom"}], "defaultStatus": "unaffected"}], "descriptions": [{"lang": "en", "value": "In `src/havegecmd.c`, the `socket_handler` function performs a credential check on the abstract UNIX socket (`\\0/sys/entropy/haveged`). However, while it detects if the connecting user is not root (`cred.uid != 0`) and prepares a negative acknowledgement (`ASCII_NAK`), it **fails to stop execution**. The code proceeds to the `switch` statement, allowing any local unprivileged user to execute privileged commands such as `MAGIC_CHROOT`.", "supportingMedia": [{"type": "text/html", "base64": false, "value": "<div><pre>In `src/havegecmd.c`, the `socket_handler` function performs a credential check on the abstract UNIX socket (`\\0/sys/entropy/haveged`). However, while it detects if the connecting user is not root (`cred.uid != 0`) and prepares a negative acknowledgement (`ASCII_NAK`), it **fails to stop execution**. The code proceeds to the `switch` statement, allowing any local unprivileged user to execute privileged commands such as `MAGIC_CHROOT`.</pre></div>"}]}], "references": [{"url": "https://bugzilla.suse.com/show_bug.cgi?id=CVE-2026-41054"}], "metrics": [{"format": "CVSS", "scenarios": [{"lang": "en", "value": "GENERAL"}], "cvssV3_1": {"version": "3.1", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "availabilityImpact": "HIGH", "baseSeverity": "HIGH", "baseScore": 7.8, "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"}}], "credits": [{"lang": "en", "value": "Dirk Mueller of SUSE", "type": "finder"}], "source": {"discovery": "INTERNAL"}, "x_generator": {"engine": "Vulnogram 0.1.0-dev"}}, "adp": [{"title": "CVE Program Container", "references": [{"url": "http://www.openwall.com/lists/oss-security/2026/05/19/3"}, {"url": "http://www.openwall.com/lists/oss-security/2026/05/19/4"}, {"url": "http://www.openwall.com/lists/oss-security/2026/05/19/5"}, {"url": "http://www.openwall.com/lists/oss-security/2026/05/20/1"}], "providerMetadata": {"orgId": "af854a3a-2127-422b-91ae-364da2661108", "shortName": "CVE", "dateUpdated": "2026-05-20T09:09:33.506Z"}}, {"metrics": [{"other": {"type": "ssvc", "content": {"timestamp": "2026-05-20T12:18:07.406504Z", "id": "CVE-2026-41054", "options": [{"Exploitation": "none"}, {"Automatable": "no"}, {"Technical Impact": "total"}], "role": "CISA Coordinator", "version": "2.0.3"}}}], "title": "CISA ADP Vulnrichment", "providerMetadata": {"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0", "shortName": "CISA-ADP", "dateUpdated": "2026-05-20T12:18:15.866Z"}}]}}