RHSA-2026:57610: Moderate: kbd security update
Moderate: kbd security update
Other sources
The kbd packages provide tools for managing console behavior on a Linux system, including the keyboard, screen fonts, virtual terminals, and font files.Security Fix(es): kbd: Local privilege escalation in openvt via incorrect process owner verification allowing passwordless root login (CVE-2026-72693) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
— Red Hat
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/kbdto a version that resolves this vulnerability.Fixed in 2.4.0-12.el9_8 - Upgrade
Upgrade
redhat/kbd-debuginfoto a version that resolves this vulnerability.Fixed in 2.4.0-12.el9_8 - Upgrade
Upgrade
redhat/kbd-debugsourceto a version that resolves this vulnerability.Fixed in 2.4.0-12.el9_8 - Upgrade
Upgrade
redhat/kbd-legacyto a version that resolves this vulnerability.Fixed in 2.4.0-12.el9_8 - Upgrade
Upgrade
redhat/kbd-miscto a version that resolves this vulnerability.Fixed in 2.4.0-12.el9_8 - Upgrade
Upgrade
redhat/kbdto a version that resolves this vulnerability.Fixed in 2.4.0-12.el9_8.aa - Upgrade
Upgrade
redhat/kbd-debuginfoto a version that resolves this vulnerability.Fixed in 2.4.0-12.el9_8.aa - Upgrade
Upgrade
redhat/kbd-debugsourceto a version that resolves this vulnerability.Fixed in 2.4.0-12.el9_8.aa - Compensating control
Mitigate CVE-2026-72693 risk in kbd/openvt by limiting access to functionality that allows running openvt or otherwise controlling which users can invoke openvt-related operations.
Event History
Frequently Asked Questions
What access does an attacker need to exploit this issue?
The issue is a local privilege escalation in openvt, so exploitation requires local access to the affected system.
What is the potential impact of successful exploitation?
Incorrect process owner verification in openvt can allow a passwordless root login, resulting in local root-level access.
Which systems and architectures are covered by this update?
The advisory covers affected kbd packages for Red Hat Enterprise Linux, including x86_64, IBM z Systems, Power little endian, and ARM 64 offerings listed in the advisory.