CVE-2026-72693

EUVD-2026-55978
`openvt -u` is intended to identify the owner of the current VT and then execute `login` as that user from a privileged context. In the documented `kbrequest`/init usage, the ownership test in `authenticate_user()` relies on `stat("/proc/<pid>/fd/0")`. `stat()` on `/proc/<pid>/fd/0` follows the symlink to the underlying TTY device node. As a result, `buf.st_uid` reflects the owner of the TTY node rather than the owner of the process holding the file descriptor. If the TTY owner returns to `root` or the getty owner after logout while an unprivileged process still has `fd 0` attached to that TTY, the check can incorrectly treat that process as belonging to the privileged console owner. Once that check succeeds, the `-u` path executes a passwordless login as the selected user. In the documented `kbrequest`/init deployment using `openvt -us`, this can result in passwordless `login -f root` on the spawned VT. This report establishes that privilege escalation path for that documented deployment; it does not claim equivalent reachability for deployments that do not use `openvt -u` from a privileged `kbrequest`/init path.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
7.8 HIGH
LOCAL
LOW
LOW
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Awaiting analysis
This vulnerability is currently awaiting analysis.
Base Score
CVSS 3.x
EPSS Score
Percentile: 4.1%
Debian logo
Debian Releases
Debian Product
Codename
kbd
bookworm
postponed
forky
vulnerable
sid
vulnerable
trixie
no-dsa
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
kbd
bionic
needs-triage
focal
needs-triage
jammy
needs-triage
noble
needs-triage
resolute
needs-triage
trusty
needs-triage
xenial
needs-triage
openSUSE logo
openSUSE / SLES Releases
openSUSE Product
Release
kbd
suse enterprise desktop 15 SP7
2.4.0-150700.15.10.1
fixed
suse enterprise sap 15 SP4
2.4.0-150400.5.12.1
fixed
suse enterprise sap 15 SP5
2.4.0-150400.5.12.1
fixed
suse enterprise sap 15 SP6
2.4.0-150400.5.12.1
fixed
suse enterprise sap 15 SP7
2.4.0-150700.15.10.1
fixed
suse enterprise server 15 SP4
2.4.0-150400.5.12.1
fixed
suse enterprise server 15 SP5
2.4.0-150400.5.12.1
fixed
suse enterprise server 15 SP6
2.4.0-150400.5.12.1
fixed
suse enterprise server 15 SP7
2.4.0-150700.15.10.1
fixed
kbd-legacy
suse enterprise desktop 15 SP7
2.4.0-150700.15.10.1
fixed
suse enterprise sap 15 SP4
2.4.0-150400.5.12.1
fixed
suse enterprise sap 15 SP5
2.4.0-150400.5.12.1
fixed
suse enterprise sap 15 SP6
2.4.0-150400.5.12.1
fixed
suse enterprise sap 15 SP7
2.4.0-150700.15.10.1
fixed
suse enterprise server 15 SP4
2.4.0-150400.5.12.1
fixed
suse enterprise server 15 SP5
2.4.0-150400.5.12.1
fixed
suse enterprise server 15 SP6
2.4.0-150400.5.12.1
fixed
suse enterprise server 15 SP7
2.4.0-150700.15.10.1
fixed
Red Hat logo
Red Hat Enterprise Linux Releases
Red Hat Product
Release
kbd
RHEL 9
0:2.4.0-12.el9_8
fixed
kbd-legacy
RHEL 9
0:2.4.0-12.el9_8
fixed
kbd-misc
RHEL 9
0:2.4.0-12.el9_8
fixed
Amazon Linux logo
Amazon Linux Releases
Amazon Package
Release
kbd
Amazon Linux 2
0:1.15.5-15.amzn2.0.1
fixed
Amazon Linux 2023
0:2.4.0-2.amzn2023.0.4
fixed
kbd-debuginfo
Amazon Linux 2
0:1.15.5-15.amzn2.0.1
fixed
Amazon Linux 2023
0:2.4.0-2.amzn2023.0.4
fixed
kbd-debugsource
Amazon Linux 2023
0:2.4.0-2.amzn2023.0.4
fixed
kbd-legacy
Amazon Linux 2
0:1.15.5-15.amzn2.0.1
fixed
Amazon Linux 2023
0:2.4.0-2.amzn2023.0.4
fixed
kbd-misc
Amazon Linux 2
0:1.15.5-15.amzn2.0.1
fixed
Amazon Linux 2023
0:2.4.0-2.amzn2023.0.4
fixed
Azure Linux logo
Azure Linux Releases
Azure Package
Release
kbd
Azure Linux 3.0
0:2.2.0-3.azl3
fixed