ELBA-2026-600986

ELBA-2026-600986 - haveged Bug Fix update

Type:BUG
Impact:NA
Release Date:2026-08-05

Description


[1.9.26-1]
- Update to 1.9.26
- Fix 100% CPU spin when --no-command is used (BZ#2492029)

[1.9.25-1]
- Update to 1.9.25
- Fix initramfs switch-root failure caused by --no-command (BZ#2491739)
- Add haveged-initramfs.service for use inside the initramfs

[1.9.24-1]
- Update to 1.9.24
- Disable command mode in long-running service (--no-command flag)
- Enable PrivateNetwork=true in systemd service
- Remove SELinux policy module (no longer needed without command mode)

[1.9.23-3]
- Fix rpminspect.yaml: use annocheck failure_severity instead of inspections toggle
(annocheck is a security inspection and cannot be disabled via inspections section)

[1.9.23-2]
- Add SELinux policy module to allow semaphore creation in /dev/shm
- Add rpminspect.yaml to waive pre-existing annocheck false positive

[1.9.23-1]
- Update to 1.9.23
- Security: use O_EXCL with sem_open to prevent semaphore pre-planting attacks
- Security: fix OOB memory access in safein()/safeout() on socket errors
- Security: reject command socket connections from different user namespaces
- Security: use O_NOFOLLOW for PID file to prevent symlink attacks
- Harden: open random device with O_CLOEXEC, restrict semaphore to 0600
- Fix stale semaphore recovery after SIGKILL
- Fix compilation when NO_COMMAND_MODE is defined

[1.9.22-1]
- Update to 1.9.22
- Fix systemd sandboxing: add ReadWritePaths=/dev/shm for semaphore creation




Updated Packages


Release/ArchitectureFilenamesha256Superseded By AdvisoryChannel Label
Oracle Linux 9 (x86_64) haveged-1.9.26-1.el9.src.rpmf7b91b96fd18f8411910d8ac1083fb394a0cd4976fd6074506e9047ac81cd6e6-ol9_x86_64_developer_EPEL
haveged-1.9.26-1.el9.x86_64.rpm354d3ebe81476f0193883874382d3555f1b968adf985c629a3c1347f1d32bf73-ol9_x86_64_developer_EPEL
haveged-devel-1.9.26-1.el9.x86_64.rpmf53701e1a6a13d19b5ce538213bf5dfd9afd21077c720bf886395090be46831d-ol9_x86_64_developer_EPEL



This page is generated automatically and has not been checked for errors or omissions. For clarification or corrections please contact the Oracle Linux ULN team

software.hardware.complete