Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-54371

Опубликовано: 29 июн. 2026
Источник: redhat
CVSS3: 6.3
EPSS Низкий

Описание

attr before version 2.6.0 contains a symlink traversal vulnerability in the getfattr and setfattr utilities that allows local attackers to escalate privileges by replacing a pathname component with a symbolic link during directory hierarchy traversal. Attackers who control a pathname component can redirect getfattr and setfattr operations to arbitrary files by substituting a symlink, leading to local privilege escalation when getfattr or setfattr is invoked by a privileged process over an attacker-controlled path.

A flaw was found in the attr package. This vulnerability allows a local attacker to perform a symlink traversal attack by replacing a pathname component with a symbolic link - either during directory hierarchy traversal by getfattr or during backup restoration by setfattr, which reads and resolves full pathnames from backup files. In both cases, when these utilities are executed by a privileged process over a path controlled by the attacker, this can lead to local privilege escalation.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10attrFix deferred
Red Hat Enterprise Linux 6attrFix deferred
Red Hat Enterprise Linux 7attrFix deferred
Red Hat Enterprise Linux 8attrFix deferred
Red Hat Enterprise Linux 9attrAffected
Red Hat OpenShift Container Platform 4rhcosFix deferred
Red Hat Hardened Imagesattr-main-2.6.0-9.1.hum1FixedRHSA-2026:3488902.07.2026

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-59
https://bugzilla.redhat.com/show_bug.cgi?id=2490283attr: Symlink Traversal Privilege Escalation via getfattr and setfattr

EPSS

Процентиль: 3%
0.00136
Низкий

6.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 7.1
ubuntu
около 1 месяца назад

attr before version 2.6.0 contains a symlink traversal vulnerability in the getfattr and setfattr utilities that allows local attackers to escalate privileges by replacing a pathname component with a symbolic link during directory hierarchy traversal. Attackers who control a pathname component can redirect getfattr and setfattr operations to arbitrary files by substituting a symlink, leading to local privilege escalation when getfattr or setfattr is invoked by a privileged process over an attacker-controlled path.

CVSS3: 7.1
nvd
около 1 месяца назад

attr before version 2.6.0 contains a symlink traversal vulnerability in the getfattr and setfattr utilities that allows local attackers to escalate privileges by replacing a pathname component with a symbolic link during directory hierarchy traversal. Attackers who control a pathname component can redirect getfattr and setfattr operations to arbitrary files by substituting a symlink, leading to local privilege escalation when getfattr or setfattr is invoked by a privileged process over an attacker-controlled path.

CVSS3: 7.1
msrc
около 1 месяца назад

attr < 2.6.0 Symlink Traversal Privilege Escalation via getfattr/setfattr

CVSS3: 7.1
debian
около 1 месяца назад

attr before version 2.6.0 contains a symlink traversal vulnerability i ...

CVSS3: 7.1
github
около 1 месяца назад

attr before version 2.6.0 contains a symlink traversal vulnerability in the getfattr and setfattr utilities that allows local attackers to escalate privileges by replacing a pathname component with a symbolic link during directory hierarchy traversal. Attackers who control a pathname component can redirect getfattr and setfattr operations to arbitrary files by substituting a symlink, leading to local privilege escalation when getfattr or setfattr is invoked by a privileged process over an attacker-controlled path.

EPSS

Процентиль: 3%
0.00136
Низкий

6.3 Medium

CVSS3