PT-2026-53273 · Acl+1 · Acl+1

·

CVE-2026-54370

·

Published

2026-06-29

·

Updated

2026-08-25

CVSS v4.0

7.2

High

VectorAV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions acl versions prior to 2.4.0
Description A time-of-check to time-of-use (TOCTOU) race condition occurs when a local attacker replaces a pathname component with a symbolic link between an lstat() check and subsequent symlink-following operations. These operations include stat(), chown(), chmod(), acl get file(), and acl set file(). If a privileged process invokes getfacl, setfacl, or chacl over a path controlled by the attacker, file access control list operations can be redirected to arbitrary files, leading to local privilege escalation.
Recommendations Update to version 2.4.0 or later.

Fix

LPE

Time Of Check To Time Of Use

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2026:42736
ALSA-2026:42739
ALSA-2026:43420
AZL-91394
CVE-2026-54370
ECHO-AE30-49BE-9CC5
OESA-2026-3079
OPENSUSE-SU-2026:11312-1
RHSA-2026:34351
RHSA-2026:42736
RHSA-2026:42739
RHSA-2026:43420

Affected Products

Rocky Linux
Acl