CVE-2026-29123: Multiple SUID Root Binaries in `xd` User Home Directory Leading to Potential Local Privilege Escalation
A SUID root-owned binary in /home/xd/terminal/XDTerminal in International Data Casting (IDC) SFX2100 on Linux allows a local actor to potentially preform local privilege escalation depending on conditions of the system via execution of the affected SUID binary. This can be via PATH hijacking, symlink abuse or shared object hijacking.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-29123?
CVE-2026-29123 is considered to be a high severity vulnerability due to the potential for local privilege escalation.
How do I fix CVE-2026-29123?
To fix CVE-2026-29123, ensure that SUID root binaries in the user home directory are removed or appropriately secured.
Who is affected by CVE-2026-29123?
CVE-2026-29123 affects users of the International Data Casting SFX2100 system running Linux.
What can an attacker do with CVE-2026-29123?
An attacker can exploit CVE-2026-29123 to execute commands with elevated privileges, potentially compromising the system.
Is there a patch for CVE-2026-29123?
As of now, there is no specific patch available for CVE-2026-29123, but following best security practices can mitigate the risk.