Acl Security Update — AlmaLinux 8 (ALSA-2026:43420)
This is a security release for AlmaLinux 8. Update the product on every affected server to the patched release — there is no workaround, and unpatched servers remain exposed until updated.
Команды исправления
EL8+ (AlmaLinux/CloudLinux/Rocky)
sudo dnf update
Что это значит по лицензии SharedLicense
Your SharedLicense license itself is not affected — this is a change in AlmaLinux 8 software, not in licensing. Update the product through its standard update channel. Licenses keep working through updates; nothing needs re-issuing or re-activating.
Access Control Lists (ACLs) are used to define fine-grained discretionary access rights for files and directories. The acl packages contain the getfacl and setfacl utilities needed for manipulating access control lists.
Security Fix(es):
* acl: Symlink traversal privilege escalation via libacl functions (CVE…
Type:
security
Severity:
important
Release date:
2026-07-22
Description:
Access Control Lists (ACLs) are used to define fine-grained discretionary access rights for files and directories. The acl packages contain the getfacl and setfacl utilities needed for manipulating access control lists.
Security Fix(es):
* acl: Symlink traversal privilege escalation via libacl functions (CVE-2026-54369)
* acl: TOCTOU Symlink Traversal via getfacl/setfacl (CVE-2026-54370)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
References:
Updated packages listed below:
| Architecture | Package | Checksum |
| aarch64 | libacl-2.4.0-1.el8_10.aarch64.rpm | 16790deebbe09f7e1e2f53e71e9a5d9813bfa045ae5bde5a92be89376a765251 |
| aarch64 | libacl-devel-2.4.0-1.el8_10.aarch64.rpm | a5c5461dae76bf92c8cc9fe35329949a37a1aa1cd97e8f893d789345cfc32ff9 |
| aarch64 | acl-2.4.0-1.el8_10.aarch64.rpm | bd47f90b950287f9821fc2f67ec5844edb25b73eaeff347e66eedeac09edd83f |
| i686 | libacl-2.4.0-1.el8_10.i686.rpm | b665b74bc276ead392ec44141257e5da903dbc093941b7dc230437f65b26da1c |
| i686 | libacl-devel-2.4.0-1.el8_10.i686.rpm | e8e5d9347daf5ff939d7905b723696f8ac0242ac18c168f572b35fb0c430862f |
| ppc64le | acl-2.4.0-1.el8_10.ppc64le.rpm | 00309e2ea5383d8ab1d00453e2ac3654034f95784a92b128c5e2d4e6f4dbc6fd |
| ppc64le | libacl-devel-2.4.0-1.el8_10.ppc64le.rpm | bf8fc9a7b7fba1e74afaf7fed7f740288c85eff6f3b6b6830ca59dd4baeed70e |
| ppc64le | libacl-2.4.0-1.el8_10.ppc64le.rpm | f5198e271ea47c782b243c335337eb1ae9a8fc583c9d786d49463c0e3af288ff |
| s390x | libacl-2.4.0-1.el8_10.s390x.rpm | 0638980d842914d7ad49c37998c46c403d0cf64a700a3c8f18d92616004f3392 |
| s390x | acl-2.4.0-1.el8_10.s390x.rpm | 316054e76c6c37ad14dfd3fd5515e61c8b0351fc18caad73b1b9ac9b5bd1d1cb |
| s390x | libacl-devel-2.4.0-1.el8_10.s390x.rpm | 519495ced0d0c690b749b6431ef077f8dd56c1035e7807d6756a7e0d46a96146 |
| x86_64 | acl-2.4.0-1.el8_10.x86_64.rpm | 1fc97a9fc69ed5ee39b22690ac3963d0d21490d9988955cc3a315082cd1b51bb |
| x86_64 | libacl-devel-2.4.0-1.el8_10.x86_64.rpm | 8e11b6a89abac8c243bef38262caec01d8cb905bbf4a1cc8a2d7eb268cffc4e6 |
| x86_64 | libacl-2.4.0-1.el8_10.x86_64.rpm | cff8b92ebf1d4c9b236d7b70b59f4a55eae33a41a25ab11ee64d6c2b376925bc |
Notes:
This page is generated automatically from Red Hat security data and has not been checked for errors. For clarification or corrections please contact the AlmaLinux Packaging Team.
Источники
Предупреждения о безопасности
Похожие предупреждения
Проверьте систему на уязвимости
Выберите продукт и операционную систему, чтобы увидеть точные команды исправления.
Проверьте свою систему