Bug 2490277 (CVE-2026-54369) - CVE-2026-54369 acl: Symlink traversal privilege escalation via libacl functions
Summary: CVE-2026-54369 acl: Symlink traversal privilege escalation via libacl functions
Keywords:
Status: NEW
Alias: CVE-2026-54369
Deadline: 2026-06-29
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
high
high
Target Milestone: ---
Assignee: Product Security
QA Contact:
URL:
Whiteboard:
Depends On: 2494174
Blocks:
TreeView+ depends on / blocked
 
Reported: 2026-06-18 10:53 UTC by OSIDB Bzimport
Modified: 2026-08-18 12:25 UTC (History)
3 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)


Links
System ID Private Priority Status Summary Last Updated
Red Hat Product Errata RHBA-2026:46358 0 None None None 2026-07-27 00:06:53 UTC
Red Hat Product Errata RHBA-2026:46361 0 None None None 2026-07-27 00:31:26 UTC
Red Hat Product Errata RHBA-2026:46503 0 None None None 2026-07-27 10:23:23 UTC
Red Hat Product Errata RHBA-2026:46711 0 None None None 2026-07-27 14:45:59 UTC
Red Hat Product Errata RHBA-2026:46957 0 None None None 2026-07-27 20:42:39 UTC
Red Hat Product Errata RHBA-2026:47097 0 None None None 2026-07-28 14:46:11 UTC
Red Hat Product Errata RHBA-2026:47774 0 None None None 2026-07-29 11:12:04 UTC
Red Hat Product Errata RHSA-2026:42736 0 None None None 2026-07-21 15:03:30 UTC
Red Hat Product Errata RHSA-2026:42739 0 None None None 2026-07-21 15:15:02 UTC
Red Hat Product Errata RHSA-2026:43420 0 None None None 2026-07-22 10:20:27 UTC
Red Hat Product Errata RHSA-2026:54769 0 None None None 2026-08-18 12:25:33 UTC

Description OSIDB Bzimport 2026-06-18 10:53:34 UTC
acl before version 2.4.0 contains a symlink traversal vulnerability in the libacl pathname-based functions acl_get_file(), acl_set_file(), acl_extended_file(), and acl_delete_def_file() that allows local attackers to escalate privileges by replacing any pathname component with a symbolic link. Attackers who control any component of a pathname processed by a privileged caller can redirect ACL read or write operations to arbitrary files or directories, enabling unauthorized manipulation of access control lists and local privilege escalation.

Comment 2 errata-xmlrpc 2026-07-21 15:03:29 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9

Via RHSA-2026:42736 https://access.redhat.com/errata/RHSA-2026:42736

Comment 3 errata-xmlrpc 2026-07-21 15:15:01 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 10

Via RHSA-2026:42739 https://access.redhat.com/errata/RHSA-2026:42739

Comment 4 errata-xmlrpc 2026-07-22 10:20:26 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8

Via RHSA-2026:43420 https://access.redhat.com/errata/RHSA-2026:43420

Comment 7 errata-xmlrpc 2026-08-18 12:25:32 UTC
This issue has been addressed in the following products:

  Red Hat OpenShift Container Platform 4.22

Via RHSA-2026:54769 https://access.redhat.com/errata/RHSA-2026:54769


Note You need to log in before you can comment on or make changes to this bug.