CVE-2026-54371
EUVD-2026-4008729.06.2026, 14:16
attr before version 2.6.0 contains a symlink traversal vulnerability in the getfattr and setfattr utilities that allows local attackers to escalate privileges by replacing a pathname component with a symbolic link during directory hierarchy traversal. Attackers who control a pathname component can redirect getfattr and setfattr operations to arbitrary files by substituting a symlink, leading to local privilege escalation when getfattr or setfattr is invoked by a privileged process over an attacker-controlled path.
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
| Vendor | Product | Version | Source |
|---|---|---|---|
| Red Hat | Red Hat Hardened Images | 2.6.0-9.1.hum1 ≤ 𝑥 < * | ADP |
| attr_project | attr | 𝑥 < 2.6.0 | CNA |
Debian Releases
Ubuntu Releases
References