CVE Vulnerabilities

CVE-2026-54369

Improper Link Resolution Before File Access ('Link Following')

Published: Jun 29, 2026 | Modified: Sep 14, 2026
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
7.1 IMPORTANT
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

acl before version 2.4.0 contains a symlink traversal vulnerability in the libacl pathname-based functions acl_get_file(), acl_set_file(), acl_extended_file(), and acl_delete_def_file() that allows local attackers to escalate privileges by replacing any pathname component with a symbolic link. Attackers who control any component of a pathname processed by a privileged caller can redirect ACL read or write operations to arbitrary files or directories, enabling unauthorized manipulation of access control lists and local privilege escalation.

Weakness

The product attempts to access a file based on the filename, but it does not properly prevent that filename from identifying a link or shortcut that resolves to an unintended resource.

Affected Software

NameVendorStart VersionEnd Version
Red Hat Enterprise Linux 10RedHatacl-0:2.4.0-1.el10_2*
Red Hat Enterprise Linux 10.0 Extended Update SupportRedHatacl-0:2.4.0-0.el10_0.1*
Red Hat Enterprise Linux 8RedHatacl-0:2.4.0-1.el8_10*
Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update SupportRedHatacl-0:2.4.0-0.el8_4.1*
Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-OnRedHatacl-0:2.4.0-0.el8_4.1*
Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update SupportRedHatacl-0:2.4.0-0.el8_6.1*
Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-OnRedHatacl-0:2.4.0-0.el8_6.1*
Red Hat Enterprise Linux 8.8 Telecommunications Update ServiceRedHatacl-0:2.4.0-0.el8_8.1*
Red Hat Enterprise Linux 8.8 Update Services for SAP SolutionsRedHatacl-0:2.4.0-0.el8_8.1*
Red Hat Enterprise Linux 9RedHatacl-0:2.4.0-1.el9_8*
Red Hat Enterprise Linux 9RedHatacl-0:2.4.0-1.el9_8*
Red Hat Enterprise Linux 9.2 Update Services for SAP SolutionsRedHatacl-0:2.4.0-0.el9_2.1*
Red Hat Enterprise Linux 9.4 Update Services for SAP SolutionsRedHatacl-0:2.4.0-0.el9_4.1*
Red Hat Enterprise Linux 9.6 Extended Update SupportRedHatacl-0:2.4.0-0.el9_6.1*
Red Hat OpenShift Container Platform 4.16RedHatopenshift/ose-rhel-coreos-9:416.94.202609281908-0*
Red Hat OpenShift Container Platform 4.17RedHatopenshift/ose-rhel-coreos-9:417.94.202609191027-0*
Red Hat OpenShift Container Platform 4.19RedHatopenshift/ose-rhel-coreos-9:4.19.9.6.202609221245-0*
Red Hat OpenShift Container Platform 4.20RedHatopenshift/ose-rhel-coreos-9:4.20.9.6.202609222234-0*
Red Hat OpenShift Container Platform 4.21RedHatopenshift/ose-rhel-coreos-9:4.21.9.6.202609230720-0*
Red Hat OpenShift Container Platform 4.22RedHatopenshift/ose-rhel-coreos-9:4.22.9.8.202608130832-0*
Cert Manager support for Red Hat OpenShift release 1.20RedHatcert-manager/jetstack-cert-manager-rhel9:1790223279*
Cert Manager support for Red Hat OpenShift release 1.20RedHatcert-manager/cert-manager-istio-csr-rhel9:1790223719*
Cert Manager support for Red Hat OpenShift release 1.20RedHatcert-manager/cert-manager-operator-rhel9:1790272426*
Cert Manager support for Red Hat OpenShift release 1.20RedHatcert-manager/jetstack-cert-manager-acmesolver-rhel9:1790589998*
Cert Manager support for Red Hat OpenShift release 1.20RedHatcert-manager/jetstack-cert-manager-rhel9:1790589912*
Cert Manager support for Red Hat OpenShift release 1.20RedHatcert-manager/cert-manager-istio-csr-rhel9:1790589914*
Cert Manager support for Red Hat OpenShift release 1.20RedHatcert-manager/cert-manager-operator-rhel9:1790589855*
Cert Manager support for Red Hat OpenShift release 1.20RedHatcert-manager/cert-manager-trust-manager-rhel9:1790598593*
Red Hat AI Inference Server 3.2RedHatrhaiis/model-opt-cuda-rhel9:1790621714*
Red Hat AI Inference Server 3.2RedHatrhaiis/vllm-cuda-rhel9:1790621718*
Red Hat AI Inference Server 3.2RedHatrhaiis/vllm-rocm-rhel9:1790621713*
Red Hat Discovery 2RedHatdiscovery/discovery-server-rhel9:1784821670*
Red Hat Discovery 2RedHatdiscovery/discovery-ui-rhel9:1784821750*
Red Hat Hardened ImagesRedHatacl-main-2.4.0-0.1.hum1*
Red Hat Insights proxy 1.5RedHatinsights-proxy/insights-proxy-container-rhel9:1786433656*
Red Hat OpenShift AI 3.0RedHatrhai/base-image-rocm-rhel9:1790276886*
Red Hat OpenShift AI 3.0RedHatrhai/base-image-tpu-rhel9:1790276884*
Red Hat OpenShift AI 3.0RedHatrhai/base-image-cpu-rhel9:1790277045*
Red Hat OpenShift AI 3.0RedHatrhai/base-image-spyre-rhel9:1790276889*
Red Hat OpenShift AI 3.0RedHatrhai/base-image-cuda-rhel9:1790276974*
Red Hat OpenShift AI 3.2RedHatrhai/base-image-tpu-rhel9:1790703497*
Red Hat OpenShift AI 3.2RedHatrhai/base-image-rocm-rhel9:1790703506*
Red Hat OpenShift AI 3.2RedHatrhai/base-image-cpu-rhel9:1790703590*
Red Hat OpenShift AI 3.2RedHatrhai/base-image-spyre-rhel9:1790703568*
Red Hat OpenShift AI 3.2RedHatrhai/base-image-cuda-rhel9:1790703586*
Red Hat OpenShift AI 3.2RedHatrhai/base-image-rocm-rhel9:1790703494*
Red Hat OpenShift AI 3.3RedHatrhai/base-image-cpu-rhel9:1790703615*
Red Hat OpenShift AI 3.3RedHatrhai/base-image-tpu-rhel9:1790703516*
Red Hat OpenShift AI 3.3RedHatrhai/base-image-rocm-6.4-rhel9:1790703524*
Red Hat OpenShift AI 3.3RedHatrhai/base-image-cuda-13.0-rhel9:1790703601*
Red Hat OpenShift AI 3.3RedHatrhai/base-image-rocm-7.0-rhel9:1790703516*
Red Hat OpenShift AI 3.3RedHatrhai/base-image-cuda-12.9-rhel9:1790703608*
Red Hat OpenShift AI 3.3RedHatrhai/base-image-spyre-rhel9:1790703579*
Red Hat OpenShift AI 3.3RedHatrhai/base-image-neuron-rhel9:1790703516*
Red Hat OpenShift AI 3.4RedHatrhai/base-image-neuron-rhel9:1790703542*
Red Hat OpenShift AI 3.4RedHatrhai/base-image-tpu-rhel9:1790703539*
Red Hat OpenShift AI 3.4RedHatrhai/base-image-gaudi-rhel9:1790703553*
Red Hat OpenShift AI 3.4RedHatrhai/base-image-cpu-rhel9:1790703631*
Red Hat OpenShift AI 3.4RedHatrhai/base-image-spyre-rhel9:1790703597*
Red Hat OpenShift AI 3.4RedHatrhai/base-image-cuda-13.0-rhel9:1790703641*
Red Hat OpenShift AI 3.4RedHatrhai/base-image-cuda-12.9-rhel9:1790703630*
Red Hat OpenShift AI 3.4RedHatrhai/base-image-rocm-7.1-rhel9:1790703541*
Red Hat OpenShift AI 3.4RedHatrhai/base-image-rocm-6.4-rhel9:1790703545*
Red Hat OpenShift AI 3.5RedHatrhai/base-image-gaudi-rhel9:1790703552*
Red Hat OpenShift AI 3.5RedHatrhai/base-image-cpu-rhel9:1790703656*
Red Hat OpenShift AI 3.5RedHatrhai/base-image-neuron-rhel9:1790703557*
Red Hat OpenShift AI 3.5RedHatrhai/base-image-rubin-rhel9:1790703707*
Red Hat OpenShift AI 3.5RedHatrhai/base-image-cuda-13.0-rhel9:1790703645*
Red Hat OpenShift AI 3.5RedHatrhai/base-image-tpu-rhel9:1790703554*
Red Hat OpenShift AI 3.5RedHatrhai/base-image-rocm-7.14-rhel9:1790703554*
Red Hat OpenShift AI 3.5RedHatrhai/base-image-spyre-rhel9:1790703630*
Red Hat OpenShift AI 3.5RedHatrhai/base-image-cuda-12.9-rhel9:1790703706*
Red Hat OpenShift distributed tracing 3.10.2RedHatrhosdt/opentelemetry-collector-rhel9:1785704636*
Red Hat Update Infrastructure 5RedHatrhui5/cds-kubernetes-rhel9:1784794818*
Red Hat Update Infrastructure 5RedHatrhui5/cds-rhel9:1784794778*
Red Hat Update Infrastructure 5RedHatrhui5/haproxy-rhel9:1784795112*
Red Hat Update Infrastructure 5RedHatrhui5/installer-rhel9:1784794289*
Red Hat Update Infrastructure 5RedHatrhui5/rhua-rhel9:1784795076*
Red Hat Update Infrastructure 5RedHatrhui5/cds-kubernetes-tp-rhel9:1787241211*
Red Hat Update Infrastructure 5RedHatrhui5/installer-tp-rhel9:1787135742*
Red Hat Update Infrastructure 5RedHatrhui5/rhua-tp-rhel9:1787241260*
AclUbuntudevel*
AclUbuntuesm-infra-legacy/trusty*
AclUbuntuesm-infra-legacy/xenial*
AclUbuntuesm-infra/bionic*
AclUbuntuesm-infra/focal*
AclUbuntujammy*
AclUbuntunoble*
AclUbuntuquesting*
AclUbunturesolute*
AclUbuntuupstream*

Potential Mitigations

  • Follow the principle of least privilege when assigning access rights to entities in a software system.
  • Denying access to a file can prevent an attacker from replacing that file with a link to a sensitive file. Ensure good compartmentalization in the system to provide protected areas that can be trusted.

References