High severity7.1NVD Advisory· Published Jun 29, 2026· Updated Sep 11, 2026
CVE-2026-54371
CVE-2026-54371
Description
attr before version 2.6.0 contains a symlink traversal vulnerability in the getfattr and setfattr utilities that allows local attackers to escalate privileges by replacing a pathname component with a symbolic link during directory hierarchy traversal. Attackers who control a pathname component can redirect getfattr and setfattr operations to arbitrary files by substituting a symlink, leading to local privilege escalation when getfattr or setfattr is invoked by a privileged process over an attacker-controlled path.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
7- osv-coords6 versionspkg:rpm/opensuse/acl&distro=openSUSE%20Leap%2016.0pkg:rpm/opensuse/attr&distro=openSUSE%20Leap%2016.0pkg:rpm/almalinux/libattr-develpkg:rpm/almalinux/libattrpkg:rpm/opensuse/acl&distro=openSUSE%20Tumbleweedpkg:rpm/almalinux/attr
< 2.4.0-160000.1.1+ 5 more
- (no CPE)range: < 2.4.0-160000.1.1
- (no CPE)range: < 2.6.0-160000.1.1
- (no CPE)range: < 2.6.0-1.el8_10
- (no CPE)range: < 2.6.0-1.el8_10
- (no CPE)range: < 2.4.0-1.1
- (no CPE)range: < 2.6.0-1.el8_10
Patches
Vulnerability mechanics
References
14- access.redhat.com/errata/RHSA-2026:34889nvd
- access.redhat.com/errata/RHSA-2026:56133nvd
- access.redhat.com/errata/RHSA-2026:59380nvd
- access.redhat.com/errata/RHSA-2026:60226nvd
- access.redhat.com/errata/RHSA-2026:61783nvd
- access.redhat.com/errata/RHSA-2026:63135nvd
- access.redhat.com/errata/RHSA-2026:63138nvd
- access.redhat.com/errata/RHSA-2026:66018nvd
- access.redhat.com/security/cve/CVE-2026-54371nvd
- bugzilla.redhat.com/show_bug.cginvd
- cgit.git.savannah.nongnu.org/cgit/attr.git/commit/nvd
- cgit.git.savannah.nongnu.org/cgit/attr.git/commit/nvd
- security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-54371.jsonnvd
- www.vulncheck.com/advisories/attr-symlink-traversal-privilege-escalation-via-getfattr-setfattrnvd
News mentions
0No linked articles in our index yet.