Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 17

Количество 17

rocky логотип

RLSA-2026:43420

8 дней назад

Important: acl security update

EPSS: Низкий
rocky логотип

RLSA-2026:42739

9 дней назад

Important: acl security update

EPSS: Низкий
rocky логотип

RLSA-2026:42736

9 дней назад

Important: acl security update

EPSS: Низкий
oracle-oval логотип

ELSA-2026-43420

9 дней назад

ELSA-2026-43420: acl security update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2026-42739

10 дней назад

ELSA-2026-42739: acl security update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2026-42736

10 дней назад

ELSA-2026-42736: acl security update (IMPORTANT)

EPSS: Низкий
ubuntu логотип

CVE-2026-54370

около 1 месяца назад

acl before version 2.4.0 contains a time-of-check to time-of-use (TOCTOU) race condition vulnerability that allows local attackers to escalate privileges by replacing a pathname component with a symbolic link between an lstat() check and subsequent symlink-following operations such as stat(), chown(), chmod(), acl_get_file(), and acl_set_file(). Attackers who control a pathname component can redirect file access control list operations to arbitrary files when getfacl, setfacl, or chacl is invoked by a privileged process over an attacker-controlled path, resulting in local privilege escalation.

CVSS3: 6.3
EPSS: Низкий
redhat логотип

CVE-2026-54370

около 1 месяца назад

acl before version 2.4.0 contains a time-of-check to time-of-use (TOCTOU) race condition vulnerability that allows local attackers to escalate privileges by replacing a pathname component with a symbolic link between an lstat() check and subsequent symlink-following operations such as stat(), chown(), chmod(), acl_get_file(), and acl_set_file(). Attackers who control a pathname component can redirect file access control list operations to arbitrary files when getfacl, setfacl, or chacl is invoked by a privileged process over an attacker-controlled path, resulting in local privilege escalation.

CVSS3: 6.3
EPSS: Низкий
nvd логотип

CVE-2026-54370

около 1 месяца назад

acl before version 2.4.0 contains a time-of-check to time-of-use (TOCTOU) race condition vulnerability that allows local attackers to escalate privileges by replacing a pathname component with a symbolic link between an lstat() check and subsequent symlink-following operations such as stat(), chown(), chmod(), acl_get_file(), and acl_set_file(). Attackers who control a pathname component can redirect file access control list operations to arbitrary files when getfacl, setfacl, or chacl is invoked by a privileged process over an attacker-controlled path, resulting in local privilege escalation.

CVSS3: 6.3
EPSS: Низкий
debian логотип

CVE-2026-54370

около 1 месяца назад

acl before version 2.4.0 contains a time-of-check to time-of-use (TOCT ...

CVSS3: 6.3
EPSS: Низкий
ubuntu логотип

CVE-2026-54369

около 1 месяца назад

acl before version 2.4.0 contains a symlink traversal vulnerability in the libacl pathname-based functions acl_get_file(), acl_set_file(), acl_extended_file(), and acl_delete_def_file() that allows local attackers to escalate privileges by replacing any pathname component with a symbolic link. Attackers who control any component of a pathname processed by a privileged caller can redirect ACL read or write operations to arbitrary files or directories, enabling unauthorized manipulation of access control lists and local privilege escalation.

CVSS3: 7.1
EPSS: Низкий
redhat логотип

CVE-2026-54369

около 1 месяца назад

acl before version 2.4.0 contains a symlink traversal vulnerability in the libacl pathname-based functions acl_get_file(), acl_set_file(), acl_extended_file(), and acl_delete_def_file() that allows local attackers to escalate privileges by replacing any pathname component with a symbolic link. Attackers who control any component of a pathname processed by a privileged caller can redirect ACL read or write operations to arbitrary files or directories, enabling unauthorized manipulation of access control lists and local privilege escalation.

CVSS3: 7.1
EPSS: Низкий
nvd логотип

CVE-2026-54369

около 1 месяца назад

acl before version 2.4.0 contains a symlink traversal vulnerability in the libacl pathname-based functions acl_get_file(), acl_set_file(), acl_extended_file(), and acl_delete_def_file() that allows local attackers to escalate privileges by replacing any pathname component with a symbolic link. Attackers who control any component of a pathname processed by a privileged caller can redirect ACL read or write operations to arbitrary files or directories, enabling unauthorized manipulation of access control lists and local privilege escalation.

CVSS3: 7.1
EPSS: Низкий
msrc логотип

CVE-2026-54369

около 1 месяца назад

acl < 2.4.0 Symlink Traversal Privilege Escalation via libacl Functions

EPSS: Низкий
debian логотип

CVE-2026-54369

около 1 месяца назад

acl before version 2.4.0 contains a symlink traversal vulnerability in ...

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-r45p-762r-6pqj

около 1 месяца назад

acl before version 2.4.0 contains a time-of-check to time-of-use (TOCTOU) race condition vulnerability that allows local attackers to escalate privileges by replacing a pathname component with a symbolic link between an lstat() check and subsequent symlink-following operations such as stat(), chown(), chmod(), acl_get_file(), and acl_set_file(). Attackers who control a pathname component can redirect file access control list operations to arbitrary files when getfacl, setfacl, or chacl is invoked by a privileged process over an attacker-controlled path, resulting in local privilege escalation.

CVSS3: 6.3
EPSS: Низкий
github логотип

GHSA-53ch-pxc8-6g72

около 1 месяца назад

acl before version 2.4.0 contains a symlink traversal vulnerability in the libacl pathname-based functions acl_get_file(), acl_set_file(), acl_extended_file(), and acl_delete_def_file() that allows local attackers to escalate privileges by replacing any pathname component with a symbolic link. Attackers who control any component of a pathname processed by a privileged caller can redirect ACL read or write operations to arbitrary files or directories, enabling unauthorized manipulation of access control lists and local privilege escalation.

CVSS3: 7.1
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
rocky логотип
RLSA-2026:43420

Important: acl security update

8 дней назад
rocky логотип
RLSA-2026:42739

Important: acl security update

9 дней назад
rocky логотип
RLSA-2026:42736

Important: acl security update

9 дней назад
oracle-oval логотип
ELSA-2026-43420

ELSA-2026-43420: acl security update (IMPORTANT)

9 дней назад
oracle-oval логотип
ELSA-2026-42739

ELSA-2026-42739: acl security update (IMPORTANT)

10 дней назад
oracle-oval логотип
ELSA-2026-42736

ELSA-2026-42736: acl security update (IMPORTANT)

10 дней назад
ubuntu логотип
CVE-2026-54370

acl before version 2.4.0 contains a time-of-check to time-of-use (TOCTOU) race condition vulnerability that allows local attackers to escalate privileges by replacing a pathname component with a symbolic link between an lstat() check and subsequent symlink-following operations such as stat(), chown(), chmod(), acl_get_file(), and acl_set_file(). Attackers who control a pathname component can redirect file access control list operations to arbitrary files when getfacl, setfacl, or chacl is invoked by a privileged process over an attacker-controlled path, resulting in local privilege escalation.

CVSS3: 6.3
0%
Низкий
около 1 месяца назад
redhat логотип
CVE-2026-54370

acl before version 2.4.0 contains a time-of-check to time-of-use (TOCTOU) race condition vulnerability that allows local attackers to escalate privileges by replacing a pathname component with a symbolic link between an lstat() check and subsequent symlink-following operations such as stat(), chown(), chmod(), acl_get_file(), and acl_set_file(). Attackers who control a pathname component can redirect file access control list operations to arbitrary files when getfacl, setfacl, or chacl is invoked by a privileged process over an attacker-controlled path, resulting in local privilege escalation.

CVSS3: 6.3
0%
Низкий
около 1 месяца назад
nvd логотип
CVE-2026-54370

acl before version 2.4.0 contains a time-of-check to time-of-use (TOCTOU) race condition vulnerability that allows local attackers to escalate privileges by replacing a pathname component with a symbolic link between an lstat() check and subsequent symlink-following operations such as stat(), chown(), chmod(), acl_get_file(), and acl_set_file(). Attackers who control a pathname component can redirect file access control list operations to arbitrary files when getfacl, setfacl, or chacl is invoked by a privileged process over an attacker-controlled path, resulting in local privilege escalation.

CVSS3: 6.3
0%
Низкий
около 1 месяца назад
debian логотип
CVE-2026-54370

acl before version 2.4.0 contains a time-of-check to time-of-use (TOCT ...

CVSS3: 6.3
0%
Низкий
около 1 месяца назад
ubuntu логотип
CVE-2026-54369

acl before version 2.4.0 contains a symlink traversal vulnerability in the libacl pathname-based functions acl_get_file(), acl_set_file(), acl_extended_file(), and acl_delete_def_file() that allows local attackers to escalate privileges by replacing any pathname component with a symbolic link. Attackers who control any component of a pathname processed by a privileged caller can redirect ACL read or write operations to arbitrary files or directories, enabling unauthorized manipulation of access control lists and local privilege escalation.

CVSS3: 7.1
0%
Низкий
около 1 месяца назад
redhat логотип
CVE-2026-54369

acl before version 2.4.0 contains a symlink traversal vulnerability in the libacl pathname-based functions acl_get_file(), acl_set_file(), acl_extended_file(), and acl_delete_def_file() that allows local attackers to escalate privileges by replacing any pathname component with a symbolic link. Attackers who control any component of a pathname processed by a privileged caller can redirect ACL read or write operations to arbitrary files or directories, enabling unauthorized manipulation of access control lists and local privilege escalation.

CVSS3: 7.1
0%
Низкий
около 1 месяца назад
nvd логотип
CVE-2026-54369

acl before version 2.4.0 contains a symlink traversal vulnerability in the libacl pathname-based functions acl_get_file(), acl_set_file(), acl_extended_file(), and acl_delete_def_file() that allows local attackers to escalate privileges by replacing any pathname component with a symbolic link. Attackers who control any component of a pathname processed by a privileged caller can redirect ACL read or write operations to arbitrary files or directories, enabling unauthorized manipulation of access control lists and local privilege escalation.

CVSS3: 7.1
0%
Низкий
около 1 месяца назад
msrc логотип
CVE-2026-54369

acl < 2.4.0 Symlink Traversal Privilege Escalation via libacl Functions

0%
Низкий
около 1 месяца назад
debian логотип
CVE-2026-54369

acl before version 2.4.0 contains a symlink traversal vulnerability in ...

CVSS3: 7.1
0%
Низкий
около 1 месяца назад
github логотип
GHSA-r45p-762r-6pqj

acl before version 2.4.0 contains a time-of-check to time-of-use (TOCTOU) race condition vulnerability that allows local attackers to escalate privileges by replacing a pathname component with a symbolic link between an lstat() check and subsequent symlink-following operations such as stat(), chown(), chmod(), acl_get_file(), and acl_set_file(). Attackers who control a pathname component can redirect file access control list operations to arbitrary files when getfacl, setfacl, or chacl is invoked by a privileged process over an attacker-controlled path, resulting in local privilege escalation.

CVSS3: 6.3
0%
Низкий
около 1 месяца назад
github логотип
GHSA-53ch-pxc8-6g72

acl before version 2.4.0 contains a symlink traversal vulnerability in the libacl pathname-based functions acl_get_file(), acl_set_file(), acl_extended_file(), and acl_delete_def_file() that allows local attackers to escalate privileges by replacing any pathname component with a symbolic link. Attackers who control any component of a pathname processed by a privileged caller can redirect ACL read or write operations to arbitrary files or directories, enabling unauthorized manipulation of access control lists and local privilege escalation.

CVSS3: 7.1
0%
Низкий
около 1 месяца назад

Уязвимостей на страницу