CVE-2026-54371
ADVISORY - debianSummary
attr before version 2.6.0 contains a symlink traversal vulnerability in the getfattr and setfattr utilities that allows local attackers to escalate privileges by replacing a pathname component with a symbolic link during directory hierarchy traversal. Attackers who control a pathname component can redirect getfattr and setfattr operations to arbitrary files by substituting a symlink, leading to local privilege escalation when getfattr or setfattr is invoked by a privileged process over an attacker-controlled path.
- attr 1:2.6.0-1 (bug https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1141107) [trixie] - attr (Will be fixed first in unstable, then point release update; not to be backported by individual patches) [bookworm] - attr (Minor issue; local symlink-traversal in recursive getfattr/setfattr; fix is a complete walk_tree rewrite, high regression risk) [bullseye] - attr (Minor issue; local symlink-traversal in recursive getfattr/setfattr; fix is a complete walk_tree rewrite, high regression risk) https://www.openwall.com/lists/oss-security/2026/06/29/1 Fixed by: https://cgit.git.savannah.nongnu.org/cgit/attr.git/commit/?id=641ea6fcc556c1f34b77efb9cd3f876dff0a0a07 (v2.6.0) Fixed by: https://cgit.git.savannah.nongnu.org/cgit/attr.git/commit/?id=3fb06b9ba314d37035d0877e6de313de754f1ac8 (v2.6.0) The fixes are based on a complete rewrite of the walk_tree helper.
EPSS Score: 0.00131 (0.031)
Common Weakness Enumeration (CWE)
ADVISORY - redhat
Improper Link Resolution Before File Access ('Link Following')
Debian
CREATED
UPDATED
ADVISORY IDCVE-2026-54371
EXPLOITABILITY SCORE
-
EXPLOITS FOUND
-
COMMON WEAKNESS ENUMERATION (CWE)-
Ubuntu
CREATED
UPDATED
ADVISORY IDCVE-2026-54371
EXPLOITABILITY SCORE
-
EXPLOITS FOUND
-
COMMON WEAKNESS ENUMERATION (CWE)-
CVSS SCORE
N/AmediumRed Hat
CREATED
UPDATED
ADVISORY IDCVE-2026-54371
EXPLOITABILITY SCORE
1.8
EXPLOITS FOUND
-
COMMON WEAKNESS ENUMERATION (CWE)