Количество 12
Количество 12
CVE-2026-54369
acl before version 2.4.0 contains a symlink traversal vulnerability in the libacl pathname-based functions acl_get_file(), acl_set_file(), acl_extended_file(), and acl_delete_def_file() that allows local attackers to escalate privileges by replacing any pathname component with a symbolic link. Attackers who control any component of a pathname processed by a privileged caller can redirect ACL read or write operations to arbitrary files or directories, enabling unauthorized manipulation of access control lists and local privilege escalation.
CVE-2026-54369
acl before version 2.4.0 contains a symlink traversal vulnerability in the libacl pathname-based functions acl_get_file(), acl_set_file(), acl_extended_file(), and acl_delete_def_file() that allows local attackers to escalate privileges by replacing any pathname component with a symbolic link. Attackers who control any component of a pathname processed by a privileged caller can redirect ACL read or write operations to arbitrary files or directories, enabling unauthorized manipulation of access control lists and local privilege escalation.
CVE-2026-54369
acl before version 2.4.0 contains a symlink traversal vulnerability in the libacl pathname-based functions acl_get_file(), acl_set_file(), acl_extended_file(), and acl_delete_def_file() that allows local attackers to escalate privileges by replacing any pathname component with a symbolic link. Attackers who control any component of a pathname processed by a privileged caller can redirect ACL read or write operations to arbitrary files or directories, enabling unauthorized manipulation of access control lists and local privilege escalation.
CVE-2026-54369
acl < 2.4.0 Symlink Traversal Privilege Escalation via libacl Functions
CVE-2026-54369
acl before version 2.4.0 contains a symlink traversal vulnerability in ...
GHSA-53ch-pxc8-6g72
acl before version 2.4.0 contains a symlink traversal vulnerability in the libacl pathname-based functions acl_get_file(), acl_set_file(), acl_extended_file(), and acl_delete_def_file() that allows local attackers to escalate privileges by replacing any pathname component with a symbolic link. Attackers who control any component of a pathname processed by a privileged caller can redirect ACL read or write operations to arbitrary files or directories, enabling unauthorized manipulation of access control lists and local privilege escalation.
RLSA-2026:43420
Important: acl security update
RLSA-2026:42739
Important: acl security update
RLSA-2026:42736
Important: acl security update
ELSA-2026-43420
ELSA-2026-43420: acl security update (IMPORTANT)
ELSA-2026-42739
ELSA-2026-42739: acl security update (IMPORTANT)
ELSA-2026-42736
ELSA-2026-42736: acl security update (IMPORTANT)
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2026-54369 acl before version 2.4.0 contains a symlink traversal vulnerability in the libacl pathname-based functions acl_get_file(), acl_set_file(), acl_extended_file(), and acl_delete_def_file() that allows local attackers to escalate privileges by replacing any pathname component with a symbolic link. Attackers who control any component of a pathname processed by a privileged caller can redirect ACL read or write operations to arbitrary files or directories, enabling unauthorized manipulation of access control lists and local privilege escalation. | CVSS3: 7.1 | 0% Низкий | около 1 месяца назад | |
CVE-2026-54369 acl before version 2.4.0 contains a symlink traversal vulnerability in the libacl pathname-based functions acl_get_file(), acl_set_file(), acl_extended_file(), and acl_delete_def_file() that allows local attackers to escalate privileges by replacing any pathname component with a symbolic link. Attackers who control any component of a pathname processed by a privileged caller can redirect ACL read or write operations to arbitrary files or directories, enabling unauthorized manipulation of access control lists and local privilege escalation. | CVSS3: 7.1 | 0% Низкий | около 1 месяца назад | |
CVE-2026-54369 acl before version 2.4.0 contains a symlink traversal vulnerability in the libacl pathname-based functions acl_get_file(), acl_set_file(), acl_extended_file(), and acl_delete_def_file() that allows local attackers to escalate privileges by replacing any pathname component with a symbolic link. Attackers who control any component of a pathname processed by a privileged caller can redirect ACL read or write operations to arbitrary files or directories, enabling unauthorized manipulation of access control lists and local privilege escalation. | CVSS3: 7.1 | 0% Низкий | около 1 месяца назад | |
CVE-2026-54369 acl < 2.4.0 Symlink Traversal Privilege Escalation via libacl Functions | 0% Низкий | около 1 месяца назад | ||
CVE-2026-54369 acl before version 2.4.0 contains a symlink traversal vulnerability in ... | CVSS3: 7.1 | 0% Низкий | около 1 месяца назад | |
GHSA-53ch-pxc8-6g72 acl before version 2.4.0 contains a symlink traversal vulnerability in the libacl pathname-based functions acl_get_file(), acl_set_file(), acl_extended_file(), and acl_delete_def_file() that allows local attackers to escalate privileges by replacing any pathname component with a symbolic link. Attackers who control any component of a pathname processed by a privileged caller can redirect ACL read or write operations to arbitrary files or directories, enabling unauthorized manipulation of access control lists and local privilege escalation. | CVSS3: 7.1 | 0% Низкий | около 1 месяца назад | |
RLSA-2026:43420 Important: acl security update | 8 дней назад | |||
RLSA-2026:42739 Important: acl security update | 9 дней назад | |||
RLSA-2026:42736 Important: acl security update | 9 дней назад | |||
ELSA-2026-43420 ELSA-2026-43420: acl security update (IMPORTANT) | 9 дней назад | |||
ELSA-2026-42739 ELSA-2026-42739: acl security update (IMPORTANT) | 10 дней назад | |||
ELSA-2026-42736 ELSA-2026-42736: acl security update (IMPORTANT) | 10 дней назад |
Уязвимостей на страницу