{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","feed_url":"https://feed.craftedsignal.io/vendors/util-linux/feed.json","home_page_url":"https://feed.craftedsignal.io/","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":7.8,"id":"CVE-2026-72693"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["util-linux"],"_cs_severities":["high"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["util-linux"],"content_html":"\u003cp\u003eCVE-2026-72693 is a local privilege escalation vulnerability in the \u003ccode\u003eopenvt\u003c/code\u003e command within the \u003ccode\u003eutil-linux\u003c/code\u003e package. The flaw exists in the \u003ccode\u003eauthenticate_user()\u003c/code\u003e function, which validates the owner of the current virtual terminal (VT) to authorize execution of \u003ccode\u003elogin\u003c/code\u003e. The function incorrectly utilizes \u003ccode\u003estat()\u003c/code\u003e on \u003ccode\u003e/proc/\u0026lt;pid\u0026gt;/fd/0\u003c/code\u003e, which resolves the file descriptor symlink to the underlying TTY device node rather than verifying the actual process owner.\u003c/p\u003e\n\u003cp\u003eIf an unprivileged process maintains an open file descriptor to a TTY after the previous user session has logged out and the TTY device ownership has reverted to \u003ccode\u003eroot\u003c/code\u003e or another privileged user, \u003ccode\u003eopenvt -u\u003c/code\u003e can be manipulated into incorrectly attributing the TTY to the privileged owner. This bypasses authentication, allowing the tool to execute a passwordless login, such as \u003ccode\u003elogin -f root\u003c/code\u003e, on the spawned VT. This vulnerability is specifically reachable in deployments using \u003ccode\u003eopenvt\u003c/code\u003e via privileged \u003ccode\u003ekbrequest\u003c/code\u003e or \u003ccode\u003einit\u003c/code\u003e paths.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows an unprivileged local user to obtain a root shell or login as another privileged user without credentials. This affects systems where \u003ccode\u003eopenvt\u003c/code\u003e is configured in a privileged execution flow, such as through system initialization scripts or keyboard request handlers.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eMonitor system logs and process execution for \u003ccode\u003eopenvt\u003c/code\u003e commands, specifically those utilizing the \u003ccode\u003e-u\u003c/code\u003e or \u003ccode\u003e-us\u003c/code\u003e flags.\u003c/li\u003e\n\u003cli\u003eAudit \u003ccode\u003ekbrequest\u003c/code\u003e and \u003ccode\u003einit\u003c/code\u003e configurations to identify if \u003ccode\u003eopenvt\u003c/code\u003e is executed with elevated privileges.\u003c/li\u003e\n\u003cli\u003eUpdate \u003ccode\u003eutil-linux\u003c/code\u003e packages to the vendor-provided security patch once available to remediate the \u003ccode\u003eauthenticate_user()\u003c/code\u003e logic flaw.\u003c/li\u003e\n\u003cli\u003eRestrict local user access to terminal device nodes where possible to prevent unprivileged processes from maintaining descriptors after session termination.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-11T09:51:01Z","date_published":"2026-08-11T09:51:01Z","id":"https://feed.craftedsignal.io/briefs/2026-08-cve-2026-72693/","summary":"A vulnerability in openvt allows local privilege escalation when authentication checks incorrectly validate TTY ownership using symlink resolution, potentially leading to passwordless root login.","title":"Local Privilege Escalation via openvt Authentication Bypass (CVE-2026-72693)","url":"https://feed.craftedsignal.io/briefs/2026-08-cve-2026-72693/"}],"language":"en","title":"CraftedSignal Threat Feed - Util-Linux","version":"https://jsonfeed.org/version/1.1"}