Back to Security Advisories
High 2026-07-22

Acl Security Update — AlmaLinux 9 (ALSA-2026:42736)

AlmaLinux 9

Access Control Lists (ACLs) are used to define fine-grained discretionary access rights for files and directories. The acl packages contain the getfacl and setfacl utilities needed for manipulating access control lists. Security Fix(es): * acl: Symlink traversal privilege escalation via libacl functions (CVE…

Access Control Lists (ACLs) are used to define fine-grained discretionary access rights for files and directories. The acl packages contain the getfacl and setfacl utilities needed for manipulating access control lists.

Security Fix(es):

* acl: Symlink traversal privilege escalation via libacl functions (CVE…

Type:
security

Severity:
important

Release date:
2026-07-22

Description:
Access Control Lists (ACLs) are used to define fine-grained discretionary access rights for files and directories. The acl packages contain the getfacl and setfacl utilities needed for manipulating access control lists.

Security Fix(es):

* acl: Symlink traversal privilege escalation via libacl functions (CVE-2026-54369)
* acl: TOCTOU Symlink Traversal via getfacl/setfacl (CVE-2026-54370)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Updated packages listed below:

Architecture Package Checksum
aarch64 libacl-2.4.0-1.el9_8.aarch64.rpm 0d77e43ff4dfa111055f2c57e20993b468ec073838665ec3617cf637a1c88354
aarch64 acl-2.4.0-1.el9_8.aarch64.rpm 9a4ab0064574eb599eaca7a32e5f677e8a142d535b1b1bade6b5d478e5276ad1
aarch64 libacl-devel-2.4.0-1.el9_8.aarch64.rpm eca06ca59b170fefa5b61c8203fbd24f298981fbef3a4749fa546605e856b5b1
i686 libacl-2.4.0-1.el9_8.i686.rpm 8a1285057f65f164204102ce65365cfc315c29728c2e34a039309897f012d0e7
i686 libacl-devel-2.4.0-1.el9_8.i686.rpm c899cd69d30cbba97d54eff686a998eb2eb96d4bf2ccce29723820b6f49a1ba6
ppc64le libacl-devel-2.4.0-1.el9_8.ppc64le.rpm 3ddc18a3d9f417beffd520eda6f94a6f822932351ed8fcf16bd5913a80fde193
ppc64le acl-2.4.0-1.el9_8.ppc64le.rpm 6456fd4d863df15f169f11e4026fb6f22be8c946183c76bed90fffa823c65bdf
ppc64le libacl-2.4.0-1.el9_8.ppc64le.rpm aa9d4c78046e2fc349d9bdee869df9f18d2cb9f269da064b4d2cf605cd3f60b8
s390x libacl-devel-2.4.0-1.el9_8.s390x.rpm 5602ce2a2f11a03716cea3f2e8a7d139c55a91dab62ef30d7dfdaf673b30b0e1
s390x libacl-2.4.0-1.el9_8.s390x.rpm c2003e89b6cc59a43d68ceb444f0f6cb75dc3fb893d7aff31196ed09b286076f
s390x acl-2.4.0-1.el9_8.s390x.rpm ec1b1ae119817b2a7ef09e06686a6aa470a489d66afa1151a81c8b3831c2a077
x86_64 libacl-devel-2.4.0-1.el9_8.x86_64.rpm 59379198854138009da4a95ce9d5ee81ebbf0f713e35efb07b01c5a561797d4a
x86_64 acl-2.4.0-1.el9_8.x86_64.rpm 832d7505a48aebc994f89d77fa70f78550b3a75316536dc2fb83ab29296d4fc4
x86_64 libacl-2.4.0-1.el9_8.x86_64.rpm 9a010dfc957f608db1f479b96de850fbff887ec10f7ee916bbbba4691bd76034

Notes:
This page is generated automatically from Red Hat security data and has not been checked for errors. For clarification or corrections please contact the AlmaLinux Packaging Team.

How to Apply the Fix

Update the affected packages on your server to the patched release, then restart the relevant services.

sudo dnf update
More Information

Check your system for vulnerabilities

Select your product and operating system to see the exact fix commands that apply to you.

Check Your System