#1144392 kbd: CVE-2026-72693

Package:
src:kbd
Source:
src:kbd
Submitter:
Moritz Mühlenhoff
Date:
2026-10-07 12:35:01 UTC
Severity:
normal
Tags:
#1144392#5
Date:
2026-08-14 15:03:48 UTC
From:
To:
Hi,

The following vulnerability was published for kdb.

CVE-2026-72693[0]:
| `openvt -u` is intended to identify the owner of the current VT and
| then execute `login` as that user from a privileged context. In the
| documented `kbrequest`/init usage, the ownership test in
| `authenticate_user()` relies on `stat("/proc/<pid>/fd/0")`. `stat()`
| on `/proc/<pid>/fd/0` follows the symlink to the underlying TTY
| device node. As a result, `buf.st_uid` reflects the owner of the TTY
| node rather than the owner of the process holding the file
| descriptor. If the TTY owner returns to `root` or the getty owner
| after logout while an unprivileged process still has `fd 0` attached
| to that TTY, the check can incorrectly treat that process as
| belonging to the privileged console owner. Once that check succeeds,
| the `-u` path executes a passwordless login as the selected user. In
| the documented `kbrequest`/init deployment using `openvt -us`, this
| can result in passwordless `login -f root` on the spawned VT. This
| report establishes that privilege escalation path for that
| documented deployment; it does not claim equivalent reachability for
| deployments that do not use `openvt -u` from a privileged
| `kbrequest`/init path.

https://bugzilla.redhat.com/show_bug.cgi?id=2462115
Fixed by: https://github.com/legionus/kbd/commit/78d5ae119742e87baa7dbe0f5c4107e7533fd698 (v2.10.0)


If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2026-72693
https://www.cve.org/CVERecord?id=CVE-2026-72693

Please adjust the affected versions in the BTS as needed.

#1144392#16
Date:
2026-10-07 10:19:56 UTC
From:
To:
We believe that the bug you reported is fixed in the latest version of
kbd, which is due to be installed in the Debian FTP archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to 1144392@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Michael Schutte <michi@debian.org> (supplier of updated kbd package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@ftp-master.debian.org)
Format: 1.8
Date: Wed, 07 Oct 2026 11:44:21 +0200
Source: kbd
Binary: kbd kbd-dbgsym kbd-udeb
Architecture: source amd64
Version: 2.10.0-1
Distribution: unstable
Urgency: medium
Maintainer: Console utilities maintainers <pkg-kbd-devel@lists.alioth.debian.org>
Changed-By: Michael Schutte <michi@debian.org>
Description:
 kbd        - Linux console font and keytable utilities
 kbd-udeb   - Linux console keyboard setup utilities (udeb)
Closes: 1144392 1148647
Changes:
 kbd (2.10.0-1) unstable; urgency=medium
 .
   * New upstream release 2.10.0.
     - Fixes a local privilege escalation bug with "openvt -u", see
       CVE-2026-72693. Closes: #1144392.
     - Enable XKB keymap conversion support via "loadkeys --xkb-layout",
       closes: #1148647. This requires the addition of a build-dependency on
       libxkbcommon-dev and results in new dependencies on libxkbcommon0 by kbd
       and on libxkbcommon0-udev by kbd-udev.
   * Update years in debian/copyright.
   * Recount Change-misleading-kbd_mode-message-for-XLATE-mode.patch,
     Miscellaneous-manpage-corrections-and-additions.patch,
     Various-fixes-to-the-openvt-utility.patch.
   * Update debian/watch to version 5.
   * Upgrade Standards-Version to 4.7.4.
     - No longer declare "Priority: optional" explicitly in debian/control.
   * Ship the upstream-provided kbdinfo(1) man page instead of one written for
     Debian.
   * Add Repository: and Repository-Browse: URLs to debian/upstream/metadata.
   * Bump debhelper-compat dependency to version 14.
     - Don't specify ${misc:Depends} and ${shlibs:Depends} in debian/control.
Checksums-Sha1:
 94fabdd8862018fd6ef1b746591bbed5dc320f96 1776 kbd_2.10.0-1.dsc
 0d5c27faa128eb4c06f6744e378663dc68966dfd 2392522 kbd_2.10.0.orig.tar.gz
 f0bddad281635c8a8bdf2fda271b8a2e699edcf9 63136 kbd_2.10.0-1.debian.tar.xz
 875e5a786946733ae0668d5645efa1ebef7ca617 608940 kbd-dbgsym_2.10.0-1_amd64.deb
 a542306ce1e5af7379b514565c280851d601eb87 70652 kbd-udeb_2.10.0-1_amd64.udeb
 568590989fddcce50893b834272341993deb48b2 6288 kbd_2.10.0-1_amd64.buildinfo
 7d75eeb7846be2691017b3a5f61c1cb43aeb4d55 387124 kbd_2.10.0-1_amd64.deb
Checksums-Sha256:
 d26d2b09dce11e179907b3463dd2645850c1bef773d4e477555ae0d678b18edd 1776 kbd_2.10.0-1.dsc
 96f8b60f9136e9e0b9261b9e63b8b4b456a2f817901e90349453387a5aa1d41c 2392522 kbd_2.10.0.orig.tar.gz
 3ea5ce5ec2f8f3877156c5c653e87e6e1917fcb41df81277ee0ebc4092b19f3c 63136 kbd_2.10.0-1.debian.tar.xz
 37071c639fe1bc05bf040bec044d491b26a75d81b566e69df117bf9b3db57644 608940 kbd-dbgsym_2.10.0-1_amd64.deb
 2e6074db7d4dbc1c9cf09532c385434981019112c34732d03ce229e5cba8bb37 70652 kbd-udeb_2.10.0-1_amd64.udeb
 6ed9853d5df0ef7f85e9258b75830c1b5e9369e6dfaf8312cfc012b424b23ccf 6288 kbd_2.10.0-1_amd64.buildinfo
 e36c5fb50b1c3e6e22538c27f7d10ac05d67c9cf8c85545f93155c6978a7af28 387124 kbd_2.10.0-1_amd64.deb
Files:
 c45866d229be532882f1ce80ea1bf23d 1776 utils optional kbd_2.10.0-1.dsc
 c8ce9e3004b2b0e8ba51e743c6e72f06 2392522 utils optional kbd_2.10.0.orig.tar.gz
 ab5eba01f37396fc924dddc0979530b2 63136 utils optional kbd_2.10.0-1.debian.tar.xz
 0b4cf0e3bdb7ff635c29e2e09467a3f6 608940 debug optional kbd-dbgsym_2.10.0-1_amd64.deb
 ef40b85447318a4824182252684387c9 70652 debian-installer optional kbd-udeb_2.10.0-1_amd64.udeb
 a92cafbface6d79ea18aaaa3ef08ed28 6288 utils optional kbd_2.10.0-1_amd64.buildinfo
 370d95972b34b4e75245c0462eb19bc7 387124 utils optional kbd_2.10.0-1_amd64.deb
-----BEGIN PGP SIGNATURE-----

iQFFBAEBCgAvFiEEFvtRe6hmw/aPERSF8+QSLx2MJhoFAmrGFrURHG1pY2hpQGRl
Ymlhbi5vcmcACgkQ8+QSLx2MJhr+hAf/RAOviJ2rIbvepzlGB3Pr25r2XRcFQtZ3
HFM5dcIt945xQ0/IoWWI2M9F3yyC4hx8ZMT0HCNJ9UEZcJA+clWvvPbRVURe7wfM
ie4Tn006eNLX+nIENVXPiXyBcsd+2qCVuRC9vSW0GtIePDd7Sx6lfJeMd3fAzfOP
WhRLh+TYhbVO1/Ow8K//8fDJKFCkPJblM60b9/E8phWMXjwAdq67d11ISW7dxD7y
Zhu3cMzzvhttv0GrXiWUlmc2/kC6KbKkkABJr6zNuu33rlqQ76KSSa0sjtZ+Q960
6HvTpKPWAVxyng1Qnn0vTwx1+qrYyp3SZk3jDtpLC7LQ49PLklnGcA==
=tXoK
-----END PGP SIGNATURE-----