CVE-2026-54369
摘要
acl before version 2.4.0 contains a symlink traversal vulnerability in the libacl pathname-based functions acl_get_file(), acl_set_file(), acl_extended_file(), and acl_delete_def_file() that allows local attackers to escalate privileges by replacing any pathname component with a symbolic link. Attackers who control any component of a pathname processed by a privileged caller can redirect ACL read or write operations to arbitrary files or directories, enabling unauthorized manipulation of access control lists and local privilege escalation.
标签
- cve:cve-2026-54369
- type:cve
- vendor:alibaba
扩展字段
{
"cve_id": "CVE-2026-54369",
"raw_pub_date": "Thu, 23 Jul 2026 16:07:59 +0800"
}