acl before version 2.4.0 contains a symlink traversal vulnerability in the libacl pathname-based functions acl_get_file(), acl_set_file(), acl_extended_file(), and acl_delete_def_file() that allows local attackers to escalate privileges by replacing any pathname component with a symbolic link. Attackers who control any component of a pathname processed by a privileged caller can redirect ACL read or write operations to arbitrary files or directories, enabling unauthorized manipulation of access control lists and local privilege escalation.
The product attempts to access a file based on the filename, but it does not properly prevent that filename from identifying a link or shortcut that resolves to an unintended resource.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Red Hat Enterprise Linux 10 | RedHat | acl-0:2.4.0-1.el10_2 | * |
| Red Hat Enterprise Linux 8 | RedHat | acl-0:2.4.0-1.el8_10 | * |
| Red Hat Enterprise Linux 9 | RedHat | acl-0:2.4.0-1.el9_8 | * |
| Red Hat Enterprise Linux 9 | RedHat | acl-0:2.4.0-1.el9_8 | * |
| Red Hat Discovery 2 | RedHat | discovery/discovery-server-rhel9:1784821670 | * |
| Red Hat Discovery 2 | RedHat | discovery/discovery-ui-rhel9:1784821750 | * |
| Red Hat Hardened Images | RedHat | acl-main-2.4.0-0.1.hum1 | * |
| Red Hat Insights proxy 1.5 | RedHat | insights-proxy/insights-proxy-container-rhel9:1786433656 | * |
| Red Hat OpenShift distributed tracing 3.10.2 | RedHat | rhosdt/opentelemetry-collector-rhel9:1785704636 | * |
| Red Hat Update Infrastructure 5 | RedHat | rhui5/cds-kubernetes-rhel9:1784794818 | * |
| Red Hat Update Infrastructure 5 | RedHat | rhui5/cds-rhel9:1784794778 | * |
| Red Hat Update Infrastructure 5 | RedHat | rhui5/haproxy-rhel9:1784795112 | * |
| Red Hat Update Infrastructure 5 | RedHat | rhui5/installer-rhel9:1784794289 | * |
| Red Hat Update Infrastructure 5 | RedHat | rhui5/rhua-rhel9:1784795076 | * |
| Acl | Ubuntu | questing | * |
| Acl | Ubuntu | upstream | * |