DEBIAN-CVE-2026-58302

Source
https://security-tracker.debian.org/tracker/CVE-2026-58302
Import Source
https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2026-58302.json
JSON Data
https://api.osv.dev/v1/vulns/DEBIAN-CVE-2026-58302
Upstream
Published
2026-06-30T02:16:26Z
Modified
2026-09-14T17:03:44Z
Severity
  • 8.4 (High) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
[none]
Details

rtapi_app in linuxcnc-uspace in LinuxCNC before 2.9.9 allows privilege escalation. It is installed SUID root and loads shared library modules via dlopen() by using a user-supplied module name. Insufficient validation of the module name allows path traversal, enabling an unprivileged local user to load an arbitrary shared library. Because the process retains elevated privileges during module loading, this results in local privilege escalation to root.

References

Affected packages

Debian:12 / linuxcnc

Package

Name
linuxcnc
Purl
pkg:deb/debian/linuxcnc?arch=source&distro=bookworm

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
2.9.0~pre1+git20230208.f1270d6ed7-1+deb12u2

Affected versions

2.*
2.9.0~pre1+git20230208.f1270d6ed7-1
2.9.0~pre1+git20230208.f1270d6ed7-1+deb12u1

Ecosystem specific

{
    "urgency":  "not yet assigned"
}

Database specific

source
"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2026-58302.json"

Debian:13 / linuxcnc

Package

Name
linuxcnc
Purl
pkg:deb/debian/linuxcnc?arch=source&distro=trixie

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
1:2.9.4-2+deb13u1

Affected versions

1:2.*
1:2.9.4-2

Ecosystem specific

{
    "urgency":  "not yet assigned"
}

Database specific

source
"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2026-58302.json"