haveged: Privilege escalation — GLSA 202608-11

A vulnerability has been discovered in haveged which could allow local privilege escalation

Affected packages

sys-apps/haveged on all architectures
Affected versions < 1.9.21
Unaffected versions >= 1.9.21

Background

haveged is a simple entropy daemon using the HAVEGE algorithm.

Description

A vulnerability has been discovered in haveged. Please review the CVE identifier referenced below for details.

Impact

Root privilege escalation may be achieved by an attacker.

Workaround

There is no known workaround at this time.

Resolution

All haveged users should upgrade to the latest version:

 # emerge --sync
 # emerge --ask --oneshot --verbose ">=sys-apps/haveged-1.9.21"
 

Alternatively, consider not using haveged anymore on modern Linux kernel versions, per https://www.openwall.com/lists/oss-security/2026/05/19/4

References

Release date
August 15, 2026

Latest revision
August 15, 2026: 1

Severity
high

Exploitable
local

Bugzilla entries