GHSA-c5g3-m8p9-m3ghHighCVSS 7.8

In `src/havegecmd.c`, the `socket_handler` function performs a credential check on the abstract...

Published
May 20, 2026
Last Modified
May 22, 2026

🔗 CVE IDs covered (1)

📋 Description

In src/havegecmd.c, the socket_handler function performs a credential check on the abstract UNIX socket (\0/sys/entropy/haveged). However, while it detects if the connecting user is not root (cred.uid != 0) and prepares a negative acknowledgement (ASCII_NAK), it fails to stop execution. The code proceeds to the switch statement, allowing any local unprivileged user to execute privileged commands such as MAGIC_CHROOT.

🔗 References (9)