CVE-2026-54369

high
Published 2026-06-29 Β· Modified 2026-06-30
CVSS v3
7.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
CVSS v4 NEW
8.4
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
VIR risk
7.1

Description

acl before version 2.4.0 contains a symlink traversal vulnerability in the libacl pathname-based functions acl_get_file(), acl_set_file(), acl_extended_file(), and acl_delete_def_file() that allows local attackers to escalate privileges by replacing any pathname component with a symbolic link. Attackers who control any component of a pathname processed by a privileged caller can redirect ACL read or write operations to arbitrary files or directories, enabling unauthorized manipulation of access control lists and local privilege escalation.

Predictions

Exploit likelihood
70%
Patch ETA
β€”

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

Mitigation details

Source: Debian Security Tracker Β· View original β†— Β· DFSG

CVE-2026-54369 NameCVE-2026-54369 SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more) Vulnerable and fixed packages The table below lists information on source packages. Source PackageReleaseVersionStatus acl (PTS)bullseye2.2.53-10vulnerable bookworm2.3.1-3vulnerable…

CVE-2026-54369

NameCVE-2026-54369
SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
acl (PTS)bullseye2.2.53-10vulnerable
bookworm2.3.1-3vulnerable
trixie2.3.2-2vulnerable
forky, sid2.3.2-3vulnerable

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
aclsource(unstable)(unfixed)

Notes

[trixie] - acl <no-dsa> (Will be fixed first in unstable, then point release update)
https://www.openwall.com/lists/oss-security/2026/06/29/1

Home - Debian Security - Source (Git)

Apply commands

text fix
Notes
[trixie] - acl <no-dsa> (Will be fixed first in unstable, then point release update)https://www.openwall.com/lists/oss-security/2026/06/29/1

OS impact

suse SUSE Affected 1 release
VersionStatusFixed in
β€” Affected β€”
debian Debian Mixed 5 releases
VersionStatusFixed in
trixie Affected β€”
sid Fixed 2.4.0-1
forky Affected β€”
bullseye Affected β€”
bookworm Affected β€”

References

CWEs

CWE-59

Community-verified mitigations for this CVE will appear above when contributors publish them.

Verify integrity in audit chain (admin only). AS-IS.