ALINUX4-SA-2026:0307
摘要
Package updates are available for Alibaba Cloud Linux 4 that fix the following vulnerabilities: CVE-2026-54369: acl before version 2.4.0 contains a symlink traversal vulnerability in the libacl pathname-based functions acl_get_file(), acl_set_file(), acl_extended_file(), and acl_delete_def_file() that allows local attackers to escalate privileges by replacing any pathname component with a symbolic link. Attackers who control any component of a pathname processed by a privileged caller can redirect ACL read or write operations to arbitrary files or directories, enabling unauthorized manipulation of access control lists and local privilege escalation. **Solution**: 请您尽快将升级到修复后的版本。修复命令如下: yum update --advisory ALINUX4-SA-2026:0307 **Affected Products**: Alinux 4
正文
Package updates are available for Alibaba Cloud Linux 4 that fix the following vulnerabilities: CVE-2026-54369: acl before version 2.4.0 contains a symlink traversal vulnerability in the libacl pathname-based functions acl_get_file(), acl_set_file(), acl_extended_file(), and acl_delete_def_file() that allows local attackers to escalate privileges by replacing any pathname component with a symbolic link. Attackers who control any component of a pathname processed by a privileged caller can redirect ACL read or write operations to arbitrary files or directories, enabling unauthorized manipulation of access control lists and local privilege escalation.
标签
- cve:cve-2026-54369
- severity:important
- type:advisory
- vendor:alibaba
扩展字段
{
"advisory_id": "ALINUX4-SA-2026:0307",
"affected_products": [
"Alinux 4"
],
"cve_ids": [
"CVE-2026-54369"
],
"raw_pub_date": "Thu, 23 Jul 2026 16:08:00 +0800",
"solution": "请您尽快将升级到修复后的版本。修复命令如下:\nyum update --advisory ALINUX4-SA-2026:0307"
}