PT-2026-53274 · Attr+3 · Attr+3

·

CVE-2026-54371

·

Published

2026-06-29

·

Updated

2026-08-31

CVSS v4.0

8.4

High

VectorAV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions attr versions prior to 2.6.0
Description A flaw in the attr component, specifically within the getfattr and setfattr utilities, allows a local attacker to perform a symlink traversal attack. By replacing a pathname component with a symbolic link during directory hierarchy traversal, an attacker can redirect operations to arbitrary files. This leads to local privilege escalation when these utilities are executed by a privileged process over a path controlled by the attacker.
Recommendations Update to version 2.6.0 or later.

Fix

LPE

Link Following

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2026:56133
ALSA-2026:59380
ALSA-2026:60226
AZL-91400
AZL-91424
CVE-2026-54371
ECHO-E81F-866F-9CB6
OESA-2026-2913
OESA-2026-2914
OESA-2026-2915
OESA-2026-2916
OESA-2026-3080
OPENSUSE-SU-2026:11312-1
RHSA-2026:34889
RHSA-2026:56133
RHSA-2026:59380
RHSA-2026:60226
USN-8691-1

Affected Products

Linuxmint
Rocky Linux
Ubuntu
Attr