PT-2026-53272 · Acl+1 · Acl+1

·

CVE-2026-54369

·

Published

2026-06-29

·

Updated

2026-08-25

CVSS v4.0

8.4

High

VectorAV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions acl versions prior to 2.4.0
Description A symlink traversal issue exists in pathname-based functions. Local attackers can escalate privileges by replacing a pathname component with a symbolic link. If an attacker controls any part of a pathname processed by a privileged caller, they can redirect ACL read or write operations to arbitrary files or directories, allowing unauthorized manipulation of access control lists. The affected functions are acl get file(), acl set file(), acl extended file(), and acl delete def file().
Recommendations Update to version 2.4.0 or later. As a temporary mitigation, restrict access to the functions acl get file(), acl set file(), acl extended file(), and acl delete def file() to prevent unauthorized pathname manipulation.

Fix

LPE

Link Following

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2026:42736
ALSA-2026:42739
ALSA-2026:43420
AZL-91397
CVE-2026-54369
ECHO-B5CE-94BD-9B5B
OESA-2026-3079
OPENSUSE-SU-2026:11312-1
RHSA-2026:34351
RHSA-2026:42736
RHSA-2026:42739
RHSA-2026:43420

Affected Products

Rocky Linux
Acl