Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 11

Количество 11

ubuntu логотип

CVE-2026-54370

около 1 месяца назад

acl before version 2.4.0 contains a time-of-check to time-of-use (TOCTOU) race condition vulnerability that allows local attackers to escalate privileges by replacing a pathname component with a symbolic link between an lstat() check and subsequent symlink-following operations such as stat(), chown(), chmod(), acl_get_file(), and acl_set_file(). Attackers who control a pathname component can redirect file access control list operations to arbitrary files when getfacl, setfacl, or chacl is invoked by a privileged process over an attacker-controlled path, resulting in local privilege escalation.

CVSS3: 6.3
EPSS: Низкий
redhat логотип

CVE-2026-54370

около 1 месяца назад

acl before version 2.4.0 contains a time-of-check to time-of-use (TOCTOU) race condition vulnerability that allows local attackers to escalate privileges by replacing a pathname component with a symbolic link between an lstat() check and subsequent symlink-following operations such as stat(), chown(), chmod(), acl_get_file(), and acl_set_file(). Attackers who control a pathname component can redirect file access control list operations to arbitrary files when getfacl, setfacl, or chacl is invoked by a privileged process over an attacker-controlled path, resulting in local privilege escalation.

CVSS3: 6.3
EPSS: Низкий
nvd логотип

CVE-2026-54370

около 1 месяца назад

acl before version 2.4.0 contains a time-of-check to time-of-use (TOCTOU) race condition vulnerability that allows local attackers to escalate privileges by replacing a pathname component with a symbolic link between an lstat() check and subsequent symlink-following operations such as stat(), chown(), chmod(), acl_get_file(), and acl_set_file(). Attackers who control a pathname component can redirect file access control list operations to arbitrary files when getfacl, setfacl, or chacl is invoked by a privileged process over an attacker-controlled path, resulting in local privilege escalation.

CVSS3: 6.3
EPSS: Низкий
debian логотип

CVE-2026-54370

около 1 месяца назад

acl before version 2.4.0 contains a time-of-check to time-of-use (TOCT ...

CVSS3: 6.3
EPSS: Низкий
github логотип

GHSA-r45p-762r-6pqj

около 1 месяца назад

acl before version 2.4.0 contains a time-of-check to time-of-use (TOCTOU) race condition vulnerability that allows local attackers to escalate privileges by replacing a pathname component with a symbolic link between an lstat() check and subsequent symlink-following operations such as stat(), chown(), chmod(), acl_get_file(), and acl_set_file(). Attackers who control a pathname component can redirect file access control list operations to arbitrary files when getfacl, setfacl, or chacl is invoked by a privileged process over an attacker-controlled path, resulting in local privilege escalation.

CVSS3: 6.3
EPSS: Низкий
rocky логотип

RLSA-2026:43420

8 дней назад

Important: acl security update

EPSS: Низкий
rocky логотип

RLSA-2026:42739

9 дней назад

Important: acl security update

EPSS: Низкий
rocky логотип

RLSA-2026:42736

9 дней назад

Important: acl security update

EPSS: Низкий
oracle-oval логотип

ELSA-2026-43420

9 дней назад

ELSA-2026-43420: acl security update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2026-42739

10 дней назад

ELSA-2026-42739: acl security update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2026-42736

10 дней назад

ELSA-2026-42736: acl security update (IMPORTANT)

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2026-54370

acl before version 2.4.0 contains a time-of-check to time-of-use (TOCTOU) race condition vulnerability that allows local attackers to escalate privileges by replacing a pathname component with a symbolic link between an lstat() check and subsequent symlink-following operations such as stat(), chown(), chmod(), acl_get_file(), and acl_set_file(). Attackers who control a pathname component can redirect file access control list operations to arbitrary files when getfacl, setfacl, or chacl is invoked by a privileged process over an attacker-controlled path, resulting in local privilege escalation.

CVSS3: 6.3
0%
Низкий
около 1 месяца назад
redhat логотип
CVE-2026-54370

acl before version 2.4.0 contains a time-of-check to time-of-use (TOCTOU) race condition vulnerability that allows local attackers to escalate privileges by replacing a pathname component with a symbolic link between an lstat() check and subsequent symlink-following operations such as stat(), chown(), chmod(), acl_get_file(), and acl_set_file(). Attackers who control a pathname component can redirect file access control list operations to arbitrary files when getfacl, setfacl, or chacl is invoked by a privileged process over an attacker-controlled path, resulting in local privilege escalation.

CVSS3: 6.3
0%
Низкий
около 1 месяца назад
nvd логотип
CVE-2026-54370

acl before version 2.4.0 contains a time-of-check to time-of-use (TOCTOU) race condition vulnerability that allows local attackers to escalate privileges by replacing a pathname component with a symbolic link between an lstat() check and subsequent symlink-following operations such as stat(), chown(), chmod(), acl_get_file(), and acl_set_file(). Attackers who control a pathname component can redirect file access control list operations to arbitrary files when getfacl, setfacl, or chacl is invoked by a privileged process over an attacker-controlled path, resulting in local privilege escalation.

CVSS3: 6.3
0%
Низкий
около 1 месяца назад
debian логотип
CVE-2026-54370

acl before version 2.4.0 contains a time-of-check to time-of-use (TOCT ...

CVSS3: 6.3
0%
Низкий
около 1 месяца назад
github логотип
GHSA-r45p-762r-6pqj

acl before version 2.4.0 contains a time-of-check to time-of-use (TOCTOU) race condition vulnerability that allows local attackers to escalate privileges by replacing a pathname component with a symbolic link between an lstat() check and subsequent symlink-following operations such as stat(), chown(), chmod(), acl_get_file(), and acl_set_file(). Attackers who control a pathname component can redirect file access control list operations to arbitrary files when getfacl, setfacl, or chacl is invoked by a privileged process over an attacker-controlled path, resulting in local privilege escalation.

CVSS3: 6.3
0%
Низкий
около 1 месяца назад
rocky логотип
RLSA-2026:43420

Important: acl security update

8 дней назад
rocky логотип
RLSA-2026:42739

Important: acl security update

9 дней назад
rocky логотип
RLSA-2026:42736

Important: acl security update

9 дней назад
oracle-oval логотип
ELSA-2026-43420

ELSA-2026-43420: acl security update (IMPORTANT)

9 дней назад
oracle-oval логотип
ELSA-2026-42739

ELSA-2026-42739: acl security update (IMPORTANT)

10 дней назад
oracle-oval логотип
ELSA-2026-42736

ELSA-2026-42736: acl security update (IMPORTANT)

10 дней назад

Уязвимостей на страницу