kbd-2.4.0-12.el9_8
エラータID: AXSA:2026-1640:01
The kbd packages provide tools for managing console behavior on a Linux system, including the keyboard, screen fonts, virtual terminals, and font files.
Security Fix(es):
* kbd: Local privilege escalation in openvt via incorrect process owner verification allowing passwordless root login (CVE-2026-72693)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
CVE-2026-72693
`openvt -u` is intended to identify the owner of the current VT and then execute `login` as that user from a privileged context. In the documented `kbrequest`/init usage, the ownership test in `authenticate_user()` relies on `stat("/proc//fd/0")`. `stat()` on `/proc//fd/0` follows the symlink to the underlying TTY device node. As a result, `buf.st_uid` reflects the owner of the TTY node rather than the owner of the process holding the file descriptor. If the TTY owner returns to `root` or the getty owner after logout while an unprivileged process still has `fd 0` attached to that TTY, the check can incorrectly treat that process as belonging to the privileged console owner. Once that check succeeds, the `-u` path executes a passwordless login as the selected user. In the documented `kbrequest`/init deployment using `openvt -us`, this can result in passwordless `login -f root` on the spawned VT. This report establishes that privilege escalation path for that documented deployment; it does not claim equivalent reachability for deployments that do not use `openvt -u` from a privileged `kbrequest`/init path.
Update packages.
`openvt -u` is intended to identify the owner of the current VT and then execute `login` as that user from a privileged context. In the documented `kbrequest`/init usage, the ownership test in `authenticate_user()` relies on `stat("/proc/<pid>/fd/0")`. `stat()` on `/proc/<pid>/fd/0` follows the symlink to the underlying TTY device node. As a result, `buf.st_uid` reflects the owner of the TTY node rather than the owner of the process holding the file descriptor. If the TTY owner returns to `root` or the getty owner after logout while an unprivileged process still has `fd 0` attached to that TTY, the check can incorrectly treat that process as belonging to the privileged console owner. Once that check succeeds, the `-u` path executes a passwordless login as the selected user. In the documented `kbrequest`/init deployment using `openvt -us`, this can result in passwordless `login -f root` on the spawned VT. This report establishes that privilege escalation path for that documented deployment; it does not claim equivalent reachability for deployments that do not use `openvt -u` from a privileged `kbrequest`/init path.
N/A
SRPMS
- kbd-2.4.0-12.el9_8.src.rpm
MD5: 202a068d499bf2a37e0c3b1cfa6a4244
SHA-256: da368c0083177ed460dc5682274d3e8562bbd42c68e1ef939ed547d90bc89f24
Size: 1.12 MB
Asianux Server 9 for x86_64
- kbd-2.4.0-12.el9_8.x86_64.rpm
MD5: cc5121cb53a8298cca25788fdb81ac80
SHA-256: 068c22def539ebbbfd47221440060e7df50ad97cde1693130b227cd0ab5626d6
Size: 409.45 kB - kbd-legacy-2.4.0-12.el9_8.noarch.rpm
MD5: d4f0c156c3249942ead4a2bbced414f1
SHA-256: 568596de9e75c92e3fbb6682cde1afecba4e7452850be09cb3879f466d7845ca
Size: 561.06 kB - kbd-misc-2.4.0-12.el9_8.noarch.rpm
MD5: 0d4581f8544036e5e9788f3c674dbd3d
SHA-256: b68d92322c1159f31eb0888d28730f13c9b75c6a4e39200e48ee3842b9b3729e
Size: 1.66 MB