acl before version 2.4.0 contains a symlink traversal vulnerability in the libacl pathname-based functions acl_get_file(), acl_set_file(), acl_extended_file(), and acl_delete_def_file() that allows local attackers to escalate privileges by replacing any pathname component with a symbolic link. Attackers who control any component of a pathname processed by a privileged caller can redirect ACL read or write operations to arbitrary files or directories, enabling unauthorized manipulation of access control lists and local privilege escalation.
CVSS Details
- CVSS 4.0 Base Score: 8.4 (HIGH)
- CVSS 4.0 Vector: (CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X)
- CVSS 3.1 Base Score: 7.1
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alma_linux | — | Upgrade libacl-develUpgrade libaclUpgrade acl | Jul 23, 2026 | Jul 21, 2026 |
| Amazon Linux Ami 2 | — | Upgrade libacl-develUpgrade aclUpgrade libaclUpgrade acl-debuginfo | Aug 5, 2026 | Aug 5, 2026 |
| Amazon_linux_2023 | — | Upgrade acl-debuginfoUpgrade libaclUpgrade libacl-debuginfoUpgrade acl-debugsourceUpgrade libacl-develUpgrade acl | Jul 21, 2026 | Jun 29, 2026 |
| Gentoo Linux | — | Upgrade sys-apps/acl.Upgrade sys-apps/attr. | Aug 20, 2026 | Aug 20, 2026 |
| Redhat Openshift | — | Upgrade rhcos | Aug 19, 2026 | Jun 29, 2026 |
| Redhat_linux | — | Upgrade libacl-develUpgrade libacl-debuginfoUpgrade aclNo solution existsUpgrade acl-debuginfoUpgrade libaclUpgrade acl-debugsource | Jul 17, 2026 | Jun 29, 2026 |
| Rocky_linux | — | Upgrade libacl-develUpgrade acl-debuginfoUpgrade libaclUpgrade acl-debugsourceUpgrade aclUpgrade libacl-debuginfo | Jul 27, 2026 | Jul 23, 2026 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | Aug 10, 2026 | Jun 29, 2026 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub