Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-54370

Опубликовано: 29 июн. 2026
Источник: redhat
CVSS3: 6.3
EPSS Низкий

Описание

acl before version 2.4.0 contains a time-of-check to time-of-use (TOCTOU) race condition vulnerability that allows local attackers to escalate privileges by replacing a pathname component with a symbolic link between an lstat() check and subsequent symlink-following operations such as stat(), chown(), chmod(), acl_get_file(), and acl_set_file(). Attackers who control a pathname component can redirect file access control list operations to arbitrary files when getfacl, setfacl, or chacl is invoked by a privileged process over an attacker-controlled path, resulting in local privilege escalation.

A time-of-check to time-of-use (TOCTOU) race condition vulnerability was found in acl. By replacing a pathname component with a symbolic link between a security check and subsequent file operations, an attacker can redirect file access control list operations. This occurs when privileged processes invoke getfacl or setfacl over an attacker-controlled path, potentially leading to local privilege escalation.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6aclFix deferred
Red Hat Enterprise Linux 7aclFix deferred
Red Hat OpenShift Container Platform 4rhcosFix deferred
Red Hat Enterprise Linux 10aclFixedRHSA-2026:4273921.07.2026
Red Hat Enterprise Linux 8aclFixedRHSA-2026:4342022.07.2026
Red Hat Enterprise Linux 9aclFixedRHSA-2026:4273621.07.2026
Red Hat Enterprise Linux 9aclFixedRHSA-2026:4273621.07.2026
Red Hat Discovery 2discovery/discovery-ui-rhel9FixedRHSA-2026:4683627.07.2026
Red Hat Hardened Imagesacl-main-2.4.0-0.1.hum1FixedRHSA-2026:3435101.07.2026
Red Hat Update Infrastructure 5rhui5/cds-kubernetes-rhel9FixedRHSA-2026:4448123.07.2026

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-367
https://bugzilla.redhat.com/show_bug.cgi?id=2490279acl: TOCTOU Symlink Traversal via getfacl/setfacl

EPSS

Процентиль: 0%
0.00088
Низкий

6.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.3
ubuntu
около 1 месяца назад

acl before version 2.4.0 contains a time-of-check to time-of-use (TOCTOU) race condition vulnerability that allows local attackers to escalate privileges by replacing a pathname component with a symbolic link between an lstat() check and subsequent symlink-following operations such as stat(), chown(), chmod(), acl_get_file(), and acl_set_file(). Attackers who control a pathname component can redirect file access control list operations to arbitrary files when getfacl, setfacl, or chacl is invoked by a privileged process over an attacker-controlled path, resulting in local privilege escalation.

CVSS3: 6.3
nvd
около 1 месяца назад

acl before version 2.4.0 contains a time-of-check to time-of-use (TOCTOU) race condition vulnerability that allows local attackers to escalate privileges by replacing a pathname component with a symbolic link between an lstat() check and subsequent symlink-following operations such as stat(), chown(), chmod(), acl_get_file(), and acl_set_file(). Attackers who control a pathname component can redirect file access control list operations to arbitrary files when getfacl, setfacl, or chacl is invoked by a privileged process over an attacker-controlled path, resulting in local privilege escalation.

CVSS3: 6.3
debian
около 1 месяца назад

acl before version 2.4.0 contains a time-of-check to time-of-use (TOCT ...

CVSS3: 6.3
github
около 1 месяца назад

acl before version 2.4.0 contains a time-of-check to time-of-use (TOCTOU) race condition vulnerability that allows local attackers to escalate privileges by replacing a pathname component with a symbolic link between an lstat() check and subsequent symlink-following operations such as stat(), chown(), chmod(), acl_get_file(), and acl_set_file(). Attackers who control a pathname component can redirect file access control list operations to arbitrary files when getfacl, setfacl, or chacl is invoked by a privileged process over an attacker-controlled path, resulting in local privilege escalation.

rocky
8 дней назад

Important: acl security update

EPSS

Процентиль: 0%
0.00088
Низкий

6.3 Medium

CVSS3