acl-2.4.0-1.el9_8

エラータID: AXSA:2026-1529:02

Release date: 
Thursday, August 13, 2026 - 22:09
Subject: 
acl-2.4.0-1.el9_8
Affected Channels: 
MIRACLE LINUX 9 for x86_64
Severity: 
High
Description: 

Access Control Lists (ACLs) are used to define fine-grained discretionary access rights for files and directories. The acl packages contain the getfacl and setfacl utilities needed for manipulating access control lists.

Security Fix(es):

* acl: Symlink traversal privilege escalation via libacl functions (CVE-2026-54369)
* acl: TOCTOU Symlink Traversal via getfacl/setfacl (CVE-2026-54370)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

CVE-2026-54369
acl before version 2.4.0 contains a symlink traversal vulnerability in the libacl pathname-based functions acl_get_file(), acl_set_file(), acl_extended_file(), and acl_delete_def_file() that allows local attackers to escalate privileges by replacing any pathname component with a symbolic link. Attackers who control any component of a pathname processed by a privileged caller can redirect ACL read or write operations to arbitrary files or directories, enabling unauthorized manipulation of access control lists and local privilege escalation.
CVE-2026-54370
acl before version 2.4.0 contains a time-of-check to time-of-use (TOCTOU) race condition vulnerability that allows local attackers to escalate privileges by replacing a pathname component with a symbolic link between an lstat() check and subsequent symlink-following operations such as stat(), chown(), chmod(), acl_get_file(), and acl_set_file(). Attackers who control a pathname component can redirect file access control list operations to arbitrary files when getfacl, setfacl, or chacl is invoked by a privileged process over an attacker-controlled path, resulting in local privilege escalation.

Solution: 

Update packages.

Additional Info: 

N/A

Download: 

SRPMS
  1. acl-2.4.0-1.el9_8.src.rpm
    MD5: 221a38ef97f2c930aa8bda173abc203a
    SHA-256: 2d07fefcccd40c6849bca24dff96625cdf5d19033ac98979a4c6e3ad4ac276f6
    Size: 589.38 kB

Asianux Server 9 for x86_64
  1. acl-2.4.0-1.el9_8.x86_64.rpm
    MD5: bcc1f8b409a7be50457fb2c859f8434c
    SHA-256: a2bcbc4f576325e5c469fad9ba9332c6b2dbd4851997c8ac09697dee5d6772ab
    Size: 79.23 kB
  2. libacl-2.4.0-1.el9_8.i686.rpm
    MD5: 2a1dbd961df5624a7263aad9996e0460
    SHA-256: b53af514f1ae80c95a63d7388f5bb79f11a64bc366f7a0f96dc0f320fd180873
    Size: 25.94 kB
  3. libacl-2.4.0-1.el9_8.x86_64.rpm
    MD5: 9b6d580dbab971fb041a4ff552df14e4
    SHA-256: f8ae70bb048d3dab174643550e5e57550c6e21e425b404073a875744a0bfaf3a
    Size: 24.66 kB
  4. libacl-devel-2.4.0-1.el9_8.i686.rpm
    MD5: 9a290b1574b664c1acd91f03d3f928ba
    SHA-256: 72ab168227597bae28f2e265f61b355df6f0657cb943160a8080bd3e6df9b5dd
    Size: 82.69 kB
  5. libacl-devel-2.4.0-1.el9_8.x86_64.rpm
    MD5: e02ffc443e75fa05be817536c55b4b43
    SHA-256: 343bc32d3b532be3f6edc82afe5a9931a95dc851cda77280927425a8b25497e6
    Size: 82.68 kB