rpm package
opensuse/acl&distro=openSUSE Tumbleweed
pkg:rpm/opensuse/acl&distro=openSUSE%20Tumbleweed
Vulnerabilities (3)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2026-54371 | Hig | 7.1 | < 2.4.0-1.1 | 2.4.0-1.1 | Jun 29, 2026 | attr before version 2.6.0 contains a symlink traversal vulnerability in the getfattr and setfattr utilities that allows local attackers to escalate privileges by replacing a pathname component with a symbolic link during directory hierarchy traversal. Attackers who control a path | |
| CVE-2026-54370 | Med | 6.3 | < 2.4.0-1.1 | 2.4.0-1.1 | Jun 29, 2026 | acl before version 2.4.0 contains a time-of-check to time-of-use (TOCTOU) race condition vulnerability that allows local attackers to escalate privileges by replacing a pathname component with a symbolic link between an lstat() check and subsequent symlink-following operations su | |
| CVE-2026-54369 | Hig | 7.1 | < 2.4.0-1.1 | 2.4.0-1.1 | Jun 29, 2026 | acl before version 2.4.0 contains a symlink traversal vulnerability in the libacl pathname-based functions acl_get_file(), acl_set_file(), acl_extended_file(), and acl_delete_def_file() that allows local attackers to escalate privileges by replacing any pathname component with a |
- affected < 2.4.0-1.1fixed 2.4.0-1.1
attr before version 2.6.0 contains a symlink traversal vulnerability in the getfattr and setfattr utilities that allows local attackers to escalate privileges by replacing a pathname component with a symbolic link during directory hierarchy traversal. Attackers who control a path
- affected < 2.4.0-1.1fixed 2.4.0-1.1
acl before version 2.4.0 contains a time-of-check to time-of-use (TOCTOU) race condition vulnerability that allows local attackers to escalate privileges by replacing a pathname component with a symbolic link between an lstat() check and subsequent symlink-following operations su
- affected < 2.4.0-1.1fixed 2.4.0-1.1
acl before version 2.4.0 contains a symlink traversal vulnerability in the libacl pathname-based functions acl_get_file(), acl_set_file(), acl_extended_file(), and acl_delete_def_file() that allows local attackers to escalate privileges by replacing any pathname component with a