acl before version 2.4.0 contains a time-of-check to time-of-use (TOCTOU) race condition vulnerability that allows local attackers to escalate privileges by replacing a pathname component with a symbolic link between an lstat() check and subsequent symlink-following operations such as stat(), chown(), chmod(), acl_get_file(), and acl_set_file(). Attackers who control a pathname component can redirect file access control list operations to arbitrary files when getfacl, setfacl, or chacl is invoked by a privileged process over an attacker-controlled path, resulting in local privilege escalation.
CVSS Details
- CVSS 4.0 Base Score: 7.2 (HIGH)
- CVSS 4.0 Vector: (CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X)
- CVSS 3.1 Base Score: 6.3
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alma_linux | — | Upgrade libacl-develUpgrade aclUpgrade libacl | Jul 23, 2026 | Jul 21, 2026 |
| Amazon_linux_2023 | — | Upgrade acl-debugsourceUpgrade acl-debuginfoUpgrade libaclUpgrade aclUpgrade libacl-develUpgrade libacl-debuginfo | Jul 21, 2026 | Jun 29, 2026 |
| Gentoo Linux | — | Upgrade sys-apps/attr.Upgrade sys-apps/acl. | Aug 20, 2026 | Aug 20, 2026 |
| Redhat_linux | — | No solution existsUpgrade acl-debuginfoUpgrade libacl-develUpgrade acl-debugsourceUpgrade libacl-debuginfoUpgrade libaclUpgrade acl | Jul 17, 2026 | Jun 29, 2026 |
| Rocky_linux | — | Upgrade acl-debugsourceUpgrade libacl-debuginfoUpgrade libacl-develUpgrade aclUpgrade acl-debuginfoUpgrade libacl | Jul 27, 2026 | Jul 23, 2026 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub