Bug 2490283 (CVE-2026-54371) - CVE-2026-54371 attr: Symlink Traversal Privilege Escalation via getfattr
Summary: CVE-2026-54371 attr: Symlink Traversal Privilege Escalation via getfattr
Keywords:
Status: NEW
Alias: CVE-2026-54371
Deadline: 2026-06-29
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
high
high
Target Milestone: ---
Assignee: Product Security DevOps Team
QA Contact:
URL:
Whiteboard:
Depends On: 2494172
Blocks:
TreeView+ depends on / blocked
 
Reported: 2026-06-18 11:03 UTC by OSIDB Bzimport
Modified: 2026-06-29 13:16 UTC (History)
5 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description OSIDB Bzimport 2026-06-18 11:03:30 UTC
attr before version 2.6.0 contains a symlink traversal vulnerability in the getfattr utility that allows local attackers to escalate privileges by replacing a pathname component with a symbolic link during directory hierarchy traversal. Attackers who control a pathname component can redirect getfattr operations to arbitrary files by substituting a symlink, leading to local privilege escalation when getfattr is invoked by a privileged process over an attacker-controlled path.


Note You need to log in before you can comment on or make changes to this bug.