Fedora Account System
Red Hat Associate
Red Hat Customer
acl before version 2.4.0 contains a symlink traversal vulnerability in the libacl pathname-based functions acl_get_file(), acl_set_file(), acl_extended_file(), and acl_delete_def_file() that allows local attackers to escalate privileges by replacing any pathname component with a symbolic link. Attackers who control any component of a pathname processed by a privileged caller can redirect ACL read or write operations to arbitrary files or directories, enabling unauthorized manipulation of access control lists and local privilege escalation.
This issue has been addressed in the following products: Red Hat Enterprise Linux 9 Via RHSA-2026:42736 https://access.redhat.com/errata/RHSA-2026:42736
This issue has been addressed in the following products: Red Hat Enterprise Linux 10 Via RHSA-2026:42739 https://access.redhat.com/errata/RHSA-2026:42739
This issue has been addressed in the following products: Red Hat Enterprise Linux 8 Via RHSA-2026:43420 https://access.redhat.com/errata/RHSA-2026:43420
This issue has been addressed in the following products: Red Hat OpenShift Container Platform 4.22 Via RHSA-2026:54769 https://access.redhat.com/errata/RHSA-2026:54769