acl before version 2.4.0 contains a time-of-check to time-of-use (TOCTOU) race condition vulnerability that allows local attackers to escalate privileges by replacing a pathname component with a symbolic link between an lstat() check and subsequent symlink-following operations such as stat(), chown(), chmod(), acl_get_file(), and acl_set_file(). Attackers who control a pathname component can redirect file access control list operations to arbitrary files when getfacl, setfacl, or chacl is invoked by a privileged process over an attacker-controlled path, resulting in local privilege escalation.
CVSS Details
- CVSS 4.0 Base Score: 7.2 (HIGH)
- CVSS 4.0 Vector: (CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X)
- CVSS 3.1 Base Score: 6.3
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alma_linux | — | Upgrade libaclUpgrade libacl-develUpgrade acl | Jul 23, 2026 | Jul 21, 2026 |
| Amazon_linux_2023 | — | Upgrade aclUpgrade libacl-debuginfoUpgrade libacl-develUpgrade libaclUpgrade acl-debugsourceUpgrade acl-debuginfo | Jul 21, 2026 | Jun 29, 2026 |
| Gentoo Linux | — | Upgrade sys-apps/attr.Upgrade sys-apps/acl. | Aug 20, 2026 | Aug 20, 2026 |
| Redhat_linux | — | Upgrade acl-debugsourceUpgrade libaclUpgrade libacl-debuginfoUpgrade aclUpgrade acl-debuginfoNo solution existsUpgrade libacl-devel | Jul 17, 2026 | Jun 29, 2026 |
| Rocky_linux | — | Upgrade libaclUpgrade libacl-develUpgrade acl-debugsourceUpgrade libacl-debuginfoUpgrade acl-debuginfoUpgrade acl | Jul 27, 2026 | Jul 23, 2026 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub