Acl Security Update — AlmaLinux 9 (ALSA-2026:42736)
Access Control Lists (ACLs) are used to define fine-grained discretionary access rights for files and directories. The acl packages contain the getfacl and setfacl utilities needed for manipulating access control lists. Security Fix(es): * acl: Symlink traversal privilege escalation via libacl functions (CVE…
Access Control Lists (ACLs) are used to define fine-grained discretionary access rights for files and directories. The acl packages contain the getfacl and setfacl utilities needed for manipulating access control lists.
Security Fix(es):
* acl: Symlink traversal privilege escalation via libacl functions (CVE…
Security Fix(es):
* acl: Symlink traversal privilege escalation via libacl functions (CVE-2026-54369)
* acl: TOCTOU Symlink Traversal via getfacl/setfacl (CVE-2026-54370)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
| Architecture | Package | Checksum |
| aarch64 | libacl-2.4.0-1.el9_8.aarch64.rpm | 0d77e43ff4dfa111055f2c57e20993b468ec073838665ec3617cf637a1c88354 |
| aarch64 | acl-2.4.0-1.el9_8.aarch64.rpm | 9a4ab0064574eb599eaca7a32e5f677e8a142d535b1b1bade6b5d478e5276ad1 |
| aarch64 | libacl-devel-2.4.0-1.el9_8.aarch64.rpm | eca06ca59b170fefa5b61c8203fbd24f298981fbef3a4749fa546605e856b5b1 |
| i686 | libacl-2.4.0-1.el9_8.i686.rpm | 8a1285057f65f164204102ce65365cfc315c29728c2e34a039309897f012d0e7 |
| i686 | libacl-devel-2.4.0-1.el9_8.i686.rpm | c899cd69d30cbba97d54eff686a998eb2eb96d4bf2ccce29723820b6f49a1ba6 |
| ppc64le | libacl-devel-2.4.0-1.el9_8.ppc64le.rpm | 3ddc18a3d9f417beffd520eda6f94a6f822932351ed8fcf16bd5913a80fde193 |
| ppc64le | acl-2.4.0-1.el9_8.ppc64le.rpm | 6456fd4d863df15f169f11e4026fb6f22be8c946183c76bed90fffa823c65bdf |
| ppc64le | libacl-2.4.0-1.el9_8.ppc64le.rpm | aa9d4c78046e2fc349d9bdee869df9f18d2cb9f269da064b4d2cf605cd3f60b8 |
| s390x | libacl-devel-2.4.0-1.el9_8.s390x.rpm | 5602ce2a2f11a03716cea3f2e8a7d139c55a91dab62ef30d7dfdaf673b30b0e1 |
| s390x | libacl-2.4.0-1.el9_8.s390x.rpm | c2003e89b6cc59a43d68ceb444f0f6cb75dc3fb893d7aff31196ed09b286076f |
| s390x | acl-2.4.0-1.el9_8.s390x.rpm | ec1b1ae119817b2a7ef09e06686a6aa470a489d66afa1151a81c8b3831c2a077 |
| x86_64 | libacl-devel-2.4.0-1.el9_8.x86_64.rpm | 59379198854138009da4a95ce9d5ee81ebbf0f713e35efb07b01c5a561797d4a |
| x86_64 | acl-2.4.0-1.el9_8.x86_64.rpm | 832d7505a48aebc994f89d77fa70f78550b3a75316536dc2fb83ab29296d4fc4 |
| x86_64 | libacl-2.4.0-1.el9_8.x86_64.rpm | 9a010dfc957f608db1f479b96de850fbff887ec10f7ee916bbbba4691bd76034 |
How to Apply the Fix
Update the affected packages on your server to the patched release, then restart the relevant services.
sudo dnf update
Check your system for vulnerabilities
Select your product and operating system to see the exact fix commands that apply to you.
Check Your System