Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-54369

Опубликовано: 29 июн. 2026
Источник: redhat
CVSS3: 7.1

Описание

acl before version 2.4.0 contains a symlink traversal vulnerability in the libacl pathname-based functions acl_get_file(), acl_set_file(), acl_extended_file(), and acl_delete_def_file() that allows local attackers to escalate privileges by replacing any pathname component with a symbolic link. Attackers who control any component of a pathname processed by a privileged caller can redirect ACL read or write operations to arbitrary files or directories, enabling unauthorized manipulation of access control lists and local privilege escalation.

A flaw was found in the acl package, specifically within its libacl pathname-based functions. A local attacker could exploit this vulnerability by using a symbolic link to replace a pathname component. This could allow the attacker to redirect access control list (ACL) read or write operations to arbitrary files or directories, leading to unauthorized manipulation of ACLs and ultimately local privilege escalation.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6aclAffected
Red Hat Enterprise Linux 7aclAffected
Red Hat OpenShift Container Platform 4rhcosAffected
Red Hat Enterprise Linux 10aclFixedRHSA-2026:4273921.07.2026
Red Hat Enterprise Linux 8aclFixedRHSA-2026:4342022.07.2026
Red Hat Enterprise Linux 9aclFixedRHSA-2026:4273621.07.2026
Red Hat Enterprise Linux 9aclFixedRHSA-2026:4273621.07.2026
Red Hat Discovery 2discovery/discovery-server-rhel9FixedRHSA-2026:4683627.07.2026
Red Hat Discovery 2discovery/discovery-ui-rhel9FixedRHSA-2026:4683627.07.2026
Red Hat Hardened Imagesacl-main-2.4.0-0.1.hum1FixedRHSA-2026:3435101.07.2026

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-59
https://bugzilla.redhat.com/show_bug.cgi?id=2490277acl: Symlink traversal privilege escalation via libacl functions

7.1 High

CVSS3

Связанные уязвимости

CVSS3: 7.1
ubuntu
около 1 месяца назад

acl before version 2.4.0 contains a symlink traversal vulnerability in the libacl pathname-based functions acl_get_file(), acl_set_file(), acl_extended_file(), and acl_delete_def_file() that allows local attackers to escalate privileges by replacing any pathname component with a symbolic link. Attackers who control any component of a pathname processed by a privileged caller can redirect ACL read or write operations to arbitrary files or directories, enabling unauthorized manipulation of access control lists and local privilege escalation.

CVSS3: 7.1
nvd
около 1 месяца назад

acl before version 2.4.0 contains a symlink traversal vulnerability in the libacl pathname-based functions acl_get_file(), acl_set_file(), acl_extended_file(), and acl_delete_def_file() that allows local attackers to escalate privileges by replacing any pathname component with a symbolic link. Attackers who control any component of a pathname processed by a privileged caller can redirect ACL read or write operations to arbitrary files or directories, enabling unauthorized manipulation of access control lists and local privilege escalation.

msrc
около 1 месяца назад

acl < 2.4.0 Symlink Traversal Privilege Escalation via libacl Functions

CVSS3: 7.1
debian
около 1 месяца назад

acl before version 2.4.0 contains a symlink traversal vulnerability in ...

CVSS3: 7.1
github
около 1 месяца назад

acl before version 2.4.0 contains a symlink traversal vulnerability in the libacl pathname-based functions acl_get_file(), acl_set_file(), acl_extended_file(), and acl_delete_def_file() that allows local attackers to escalate privileges by replacing any pathname component with a symbolic link. Attackers who control any component of a pathname processed by a privileged caller can redirect ACL read or write operations to arbitrary files or directories, enabling unauthorized manipulation of access control lists and local privilege escalation.

7.1 High

CVSS3