{"id":"CVE-2026-54371","title":"attr before version 2.6.0 contains a symlink traversal vulnerability in the getfattr and setfattr utilities that allows local attackers to escalate privileges by replacing a pathname component with a symbolic link during directory hierar…","summary":"attr before version 2.6.0 contains a symlink traversal vulnerability in the getfattr and setfattr utilities that allows local attackers to escalate privileges by replacing a pathname component with a symbolic link during directory hierar…","severity":"high","cvss":7.1,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N","cwe":["CWE-59"],"vendor":"attr project","product":"attr","affected":["attr < 2.6.0"],"patched":["enterprise_linux_appstream_v_10","enterprise_linux_appstream_v_9","enterprise_linux_baseos_v_10","enterprise_linux_baseos_v_8","enterprise_linux_baseos_v_9","cert_manager_support_for_red_hat_openshift_release 1.19","discovery 2","hardened_images"],"published":"2026-06-29","updated":"2026-09-11","sourceUpdated":"2026-09-11T13:18:15.587","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-54371","references":[{"url":"https://cgit.git.savannah.nongnu.org/cgit/attr.git/commit/?id=49f79e947270f06940b9100fa638f85dddc4aa7f","label":"disclosure@vulncheck.com"},{"url":"https://cgit.git.savannah.nongnu.org/cgit/attr.git/commit/?id=c440855d6b33446edf4b5eb1a2d892281f15a99b","label":"disclosure@vulncheck.com"},{"url":"https://www.vulncheck.com/advisories/attr-symlink-traversal-privilege-escalation-via-getfattr-setfattr","label":"disclosure@vulncheck.com"},{"url":"https://access.redhat.com/errata/RHSA-2026:34889","label":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:56133","label":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:59380","label":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:60226","label":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:61783","label":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:63135","label":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:63138","label":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:66018","label":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/security/cve/CVE-2026-54371","label":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2490283","label":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-54371.json","label":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-54371"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-54371"}],"tags":["nvd","cve.org","csaf","vex","red-hat"],"ssvc":{"exploitation":"none","automatable":"no","technicalImpact":"partial","timestamp":"2026-06-30T14:41:00.558077Z"},"epss":0.00146,"epssPercentile":0.04202,"scores":{"nvd":7.1,"vendor":6.3,"cna":7.1},"ingestedAt":"2026-07-03T20:53:53.285Z","slug":"CVE-2026-54371","body":"## Overview\n\nattr before version 2.6.0 contains a symlink traversal vulnerability in the getfattr and setfattr utilities that allows local attackers to escalate privileges by replacing a pathname component with a symbolic link during directory hierarchy traversal. Attackers who control a pathname component can redirect getfattr and setfattr operations to arbitrary files by substituting a symlink, leading to local privilege escalation when getfattr or setfattr is invoked by a privileged process over an attacker-controlled path.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.\n\n## Vendor advisories\n\n- **RHSA-2026:59380** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream (v. 10), Red Hat Enterprise Linux BaseOS (v. 10) · released 2026-08-25 · [advisory](https://access.redhat.com/errata/RHSA-2026:59380)\n- **RHSA-2026:60226** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream (v. 9), Red Hat Enterprise Linux BaseOS (v. 9) · released 2026-08-26 · [advisory](https://access.redhat.com/errata/RHSA-2026:60226)\n- **RHSA-2026:56133** · Red Hat · fixed in: Red Hat Enterprise Linux BaseOS (v. 8) · released 2026-08-18 · [advisory](https://access.redhat.com/errata/RHSA-2026:56133)\n- **RHSA-2026:63135** · Red Hat · fixed in: Cert Manager support for Red Hat OpenShift release 1.19 · released 2026-09-03 · [advisory](https://access.redhat.com/errata/RHSA-2026:63135)\n- **RHSA-2026:63138** · Red Hat · fixed in: Cert Manager support for Red Hat OpenShift release 1.19 · released 2026-09-03 · [advisory](https://access.redhat.com/errata/RHSA-2026:63138)\n- **RHSA-2026:61783** · Red Hat · fixed in: Red Hat Discovery 2 · released 2026-08-31 · [advisory](https://access.redhat.com/errata/RHSA-2026:61783)\n- **RHSA-2026:34889** · Red Hat · fixed in: Red Hat Hardened Images · released 2026-07-02 · [advisory](https://access.redhat.com/errata/RHSA-2026:34889)\n- **Red Hat VEX** · Moderate · affected: Red Hat Enterprise Linux 6, Red Hat Enterprise Linux 7, Red Hat OpenShift Container Platform 4 · no fix planned: Red Hat Enterprise Linux 6, Red Hat Enterprise Linux 7, Red Hat OpenShift Container Platform 4 · updated 2026-09-10 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-54371.json)\n- **RHSA-2026:66018** · Red Hat · fixed in: Red Hat Update Infrastructure 5 · released 2026-09-09 · [advisory](https://access.redhat.com/errata/RHSA-2026:66018)","depth":"twilight","depthScore":39,"depthScoreParts":{"impact":39.1,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}