acl-2.4.0-1.el8

エラータID: AXSA:2026-1434:01

Release date: 
Tuesday, August 4, 2026 - 14:47
Subject: 
acl-2.4.0-1.el8
Affected Channels: 
Asianux Server 8 for x86_64
Severity: 
High
Description: 

Access Control Lists (ACLs) are used to define fine-grained discretionary access rights for files and directories. The acl packages contain the getfacl and setfacl utilities needed for manipulating access control lists.

Security Fix(es):

* acl: Symlink traversal privilege escalation via libacl functions (CVE-2026-54369)
* acl: TOCTOU Symlink Traversal via getfacl/setfacl (CVE-2026-54370)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

CVE-2026-54369
acl before version 2.4.0 contains a symlink traversal vulnerability in the libacl pathname-based functions acl_get_file(), acl_set_file(), acl_extended_file(), and acl_delete_def_file() that allows local attackers to escalate privileges by replacing any pathname component with a symbolic link. Attackers who control any component of a pathname processed by a privileged caller can redirect ACL read or write operations to arbitrary files or directories, enabling unauthorized manipulation of access control lists and local privilege escalation.
CVE-2026-54370
acl before version 2.4.0 contains a time-of-check to time-of-use (TOCTOU) race condition vulnerability that allows local attackers to escalate privileges by replacing a pathname component with a symbolic link between an lstat() check and subsequent symlink-following operations such as stat(), chown(), chmod(), acl_get_file(), and acl_set_file(). Attackers who control a pathname component can redirect file access control list operations to arbitrary files when getfacl, setfacl, or chacl is invoked by a privileged process over an attacker-controlled path, resulting in local privilege escalation.

Solution: 

Update packages.

Additional Info: 

N/A

Download: 

SRPMS
  1. acl-2.4.0-1.el8.src.rpm
    MD5: 44899cd1de45e547ae089e08894ab5dc
    SHA-256: 9ac39d17f153e45fb3823f10bd410ffdab66796e055edfbcd82988d43c53df71
    Size: 599.51 kB

Asianux Server 8 for x86_64
  1. acl-2.4.0-1.el8.x86_64.rpm
    MD5: 2e31be34018ce830ae5d528f8ee067f0
    SHA-256: 7e9e613a571d2ab7bf23c362636b38e233c4391a6ecc6863437d188b7de1a7f8
    Size: 85.14 kB
  2. libacl-2.4.0-1.el8.i686.rpm
    MD5: 16bdc96ba5431b6d912295a5737070ae
    SHA-256: e874a5d3ab251358916704c1c8869a4e605b78c116ed51e866ae9887236f62d7
    Size: 39.43 kB
  3. libacl-2.4.0-1.el8.x86_64.rpm
    MD5: a3a922c01f1f0709d8dedb8785cf50a1
    SHA-256: 7fe266522c21e8d342c3b7531c00322d06e66163142f9ac64f2c191e29478ea3
    Size: 37.34 kB
  4. libacl-devel-2.4.0-1.el8.i686.rpm
    MD5: 5866012ac39f70f9565b967f40761aec
    SHA-256: 4f5a07d4b70d84692830911581bd65856c2f37a34352c0d396585d89109ac86a
    Size: 82.21 kB
  5. libacl-devel-2.4.0-1.el8.x86_64.rpm
    MD5: 8a5784b717d5e6f2705ca4844dc56060
    SHA-256: b322e4dee9e6f7d861531500fd665411d7a95b969415b47ec12c578a8e70c4ff
    Size: 82.19 kB