Back to Security Advisories
High 2026-07-22

Acl Security Update — AlmaLinux 8 (ALSA-2026:43420)

AlmaLinux 8

Access Control Lists (ACLs) are used to define fine-grained discretionary access rights for files and directories. The acl packages contain the getfacl and setfacl utilities needed for manipulating access control lists. Security Fix(es): * acl: Symlink traversal privilege escalation via libacl functions (CVE…

Access Control Lists (ACLs) are used to define fine-grained discretionary access rights for files and directories. The acl packages contain the getfacl and setfacl utilities needed for manipulating access control lists.

Security Fix(es):

* acl: Symlink traversal privilege escalation via libacl functions (CVE…

Type:
security

Severity:
important

Release date:
2026-07-22

Description:
Access Control Lists (ACLs) are used to define fine-grained discretionary access rights for files and directories. The acl packages contain the getfacl and setfacl utilities needed for manipulating access control lists.

Security Fix(es):

* acl: Symlink traversal privilege escalation via libacl functions (CVE-2026-54369)
* acl: TOCTOU Symlink Traversal via getfacl/setfacl (CVE-2026-54370)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Updated packages listed below:

Architecture Package Checksum
aarch64 libacl-2.4.0-1.el8_10.aarch64.rpm 16790deebbe09f7e1e2f53e71e9a5d9813bfa045ae5bde5a92be89376a765251
aarch64 libacl-devel-2.4.0-1.el8_10.aarch64.rpm a5c5461dae76bf92c8cc9fe35329949a37a1aa1cd97e8f893d789345cfc32ff9
aarch64 acl-2.4.0-1.el8_10.aarch64.rpm bd47f90b950287f9821fc2f67ec5844edb25b73eaeff347e66eedeac09edd83f
i686 libacl-2.4.0-1.el8_10.i686.rpm b665b74bc276ead392ec44141257e5da903dbc093941b7dc230437f65b26da1c
i686 libacl-devel-2.4.0-1.el8_10.i686.rpm e8e5d9347daf5ff939d7905b723696f8ac0242ac18c168f572b35fb0c430862f
ppc64le acl-2.4.0-1.el8_10.ppc64le.rpm 00309e2ea5383d8ab1d00453e2ac3654034f95784a92b128c5e2d4e6f4dbc6fd
ppc64le libacl-devel-2.4.0-1.el8_10.ppc64le.rpm bf8fc9a7b7fba1e74afaf7fed7f740288c85eff6f3b6b6830ca59dd4baeed70e
ppc64le libacl-2.4.0-1.el8_10.ppc64le.rpm f5198e271ea47c782b243c335337eb1ae9a8fc583c9d786d49463c0e3af288ff
s390x libacl-2.4.0-1.el8_10.s390x.rpm 0638980d842914d7ad49c37998c46c403d0cf64a700a3c8f18d92616004f3392
s390x acl-2.4.0-1.el8_10.s390x.rpm 316054e76c6c37ad14dfd3fd5515e61c8b0351fc18caad73b1b9ac9b5bd1d1cb
s390x libacl-devel-2.4.0-1.el8_10.s390x.rpm 519495ced0d0c690b749b6431ef077f8dd56c1035e7807d6756a7e0d46a96146
x86_64 acl-2.4.0-1.el8_10.x86_64.rpm 1fc97a9fc69ed5ee39b22690ac3963d0d21490d9988955cc3a315082cd1b51bb
x86_64 libacl-devel-2.4.0-1.el8_10.x86_64.rpm 8e11b6a89abac8c243bef38262caec01d8cb905bbf4a1cc8a2d7eb268cffc4e6
x86_64 libacl-2.4.0-1.el8_10.x86_64.rpm cff8b92ebf1d4c9b236d7b70b59f4a55eae33a41a25ab11ee64d6c2b376925bc

Notes:
This page is generated automatically from Red Hat security data and has not been checked for errors. For clarification or corrections please contact the AlmaLinux Packaging Team.

How to Apply the Fix

Update the affected packages on your server to the patched release, then restart the relevant services.

sudo dnf update
More Information

Check your system for vulnerabilities

अपना उत्पाद और ऑपरेटिंग सिस्टम चुनें ताकि आपके लिए लागू सटीक फिक्स कमांड देख सकें।

Check Your System