The (1) setfacl and (2) getfacl commands in XFS acl 2.2.47, when running in recursive (-R) mode, follow symbolic links even when the --physical (aka -P) or -L option is specified, which might allow local users to modify the ACL for arbitrary files or directories via a symlink attack.
CVSS Details
- CVSS 3.1 Base Score: 5.5
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade acl | Jul 30, 2024 | Dec 24, 2009 |
| Gentoo Linux | — | Upgrade app-arch/ncompress.Upgrade dev-lang/tk.Upgrade x11-libs/gtk+.Upgrade app-text/dvipng.Upgrade dev-perl/perl-tk.Upgrade sys-apps/pmount.Upgrade app-misc/beanstalkd.Upgrade net-ftp/lftp.Upgrade dev-util/sourcenav.Upgrade net-misc/iputils.Upgrade app-arch/gzip.Upgrade dev-libs/liblzw.Upgrade x11-misc/slim.Upgrade dev-util/insight.Upgrade sys-apps/acl.Upgrade sys-auth/pam_krb5.Upgrade media-tv/dvbstreamer.Upgrade kde-base/kdm.Upgrade app-text/gv.Upgrade kde-base/kget.Upgrade net-mail/mlmmj.Upgrade www-client/uzbl.Upgrade sys-devel/m4.Upgrade app-antivirus/bitdefender-console.Upgrade media-gfx/splashutils.Upgrade sys-block/partimage.Upgrade x11-apps/xinit. | Oct 30, 2017 | Dec 24, 2009 |
| Suse | — | Upgrade aclUpgrade libacl-32bitUpgrade libacl-x86Upgrade libacl | Feb 17, 2015 | Jun 28, 2013 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub