Multiple symlink traversal vulnerabilities in the Linux attr and acl packages can let a local attacker escalate privileges when privileged processes operate on attacker-controlled paths. The disclosed issues include CVE-2026-54371 in getfattr and setfattr, and CVE-2026-54369 in pathname-based libacl functions; an accompanying security notice also identifies CVE-2026-54370 affecting getfacl, setfacl, and chacl. In each case, an attacker can replace a pathname component with a symbolic link during directory traversal, redirecting file or ACL operations to unintended targets and enabling unauthorized changes to arbitrary files or directories.

Get the actors, campaigns, and ATT&CK mapping behind it.
2 events from the most recent confirmed update back to the earliest known activity.
The disclosed flaws were fixed in acl version 2.4.0 and attr version 2.6.0. The fixes added symlink-safe libacl APIs and reworked affected utilities to use safer path resolution and directory file descriptor handling.
A security notice disclosed multiple symbolic-link handling vulnerabilities in the acl and attr packages that could enable local privilege escalation when privileged users invoke affected utilities or libacl functions on attacker-controlled paths. The issues were assigned CVE-2026-54369, CVE-2026-54370, and CVE-2026-54371.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Get the adversaries, campaigns, and ATT&CK mapping behind this technique, with detections ready to deploy.
4 references tracked. Mallory keeps watching after this page renders.
cvefeed.io
Open sourcecvefeed.io
Open sourceseclists.org
Open sourceseclists.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.