---
id: CVE-2026-54369
title: >-
  acl: Symlink traversal privilege escalation via libacl functions
  (CVE-2026-54369)
summary: >-
  A flaw was found in the `acl` package, specifically within its `libacl`
  pathname-based functions. A local attacker could exploit this vulnerability by
  using a symbolic link to replace a pathname component. This could allow the
  attacker to …
severity: high
cvss: 7.1
cvssVector: 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N'
cvssSource: vendor
cwe: CWE-59
vendor: Red Hat
product: Red Hat Enterprise Linux BaseOS E4S (v.8.8)
affected:
  - enterprise_linux 6
  - enterprise_linux 7
  - openshift_container_platform 4
  - openshift_container_platform 4.22
  - enterprise_linux_appstream_eus_v_10_0
  - enterprise_linux_appstream_v_10
  - enterprise_linux_appstream_e4s_v_9_2
  - enterprise_linux_appstream_e4s_v_9_4
  - enterprise_linux_appstream_eus_v_9_6
  - enterprise_linux_appstream_v_9
  - enterprise_linux_baseos_eus_v_10_0
  - enterprise_linux_baseos_v_10
  - enterprise_linux_baseos_v_8
  - enterprise_linux_baseos_e4s_v_8_8
  - enterprise_linux_baseos_tus_v_8_8
  - enterprise_linux_baseos_e4s_v_9_2
  - enterprise_linux_baseos_e4s_v_9_4
  - enterprise_linux_baseos_eus_v_9_6
  - enterprise_linux_baseos_v_9
  - discovery 2
  - hardened_images
  - insights_proxy 1.5
  - openshift_distributed_tracing 3.10.2
  - update_infrastructure 5
patched:
  - openshift_container_platform 4.22
  - enterprise_linux_appstream_eus_v_10_0
  - enterprise_linux_appstream_v_10
  - enterprise_linux_appstream_e4s_v_9_2
  - enterprise_linux_appstream_e4s_v_9_4
  - enterprise_linux_appstream_eus_v_9_6
  - enterprise_linux_appstream_v_9
  - enterprise_linux_baseos_eus_v_10_0
  - enterprise_linux_baseos_v_10
  - enterprise_linux_baseos_v_8
  - enterprise_linux_baseos_e4s_v_8_8
  - enterprise_linux_baseos_tus_v_8_8
  - enterprise_linux_baseos_e4s_v_9_2
  - enterprise_linux_baseos_e4s_v_9_4
  - enterprise_linux_baseos_eus_v_9_6
  - enterprise_linux_baseos_v_9
  - discovery 2
  - hardened_images
  - insights_proxy 1.5
  - openshift_distributed_tracing 3.10.2
  - update_infrastructure 5
published: '2026-06-29'
updated: '2026-09-24'
sourceUpdated: '2026-09-24T21:32:06+00:00'
source: CSAF
sourceUrl: 'https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-54369.json'
references:
  - url: >-
      https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-54369.json
  - url: 'https://access.redhat.com/security/cve/CVE-2026-54369'
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2490277'
  - url: 'https://www.cve.org/CVERecord?id=CVE-2026-54369'
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2026-54369'
  - url: 'https://access.redhat.com/errata/RHSA-2026:54769'
  - url: 'https://access.redhat.com/errata/RHSA-2026:64805'
  - url: 'https://access.redhat.com/errata/RHSA-2026:42739'
  - url: 'https://access.redhat.com/errata/RHSA-2026:67142'
  - url: 'https://access.redhat.com/errata/RHSA-2026:67144'
  - url: 'https://access.redhat.com/errata/RHSA-2026:67140'
  - url: 'https://access.redhat.com/errata/RHSA-2026:42736'
  - url: 'https://access.redhat.com/errata/RHSA-2026:43420'
  - url: 'https://access.redhat.com/errata/RHSA-2026:71656'
  - url: 'https://access.redhat.com/errata/RHSA-2026:46836'
  - url: 'https://access.redhat.com/errata/RHSA-2026:34351'
  - url: 'https://access.redhat.com/errata/RHSA-2026:53371'
  - url: 'https://access.redhat.com/errata/RHSA-2026:50205'
  - url: 'https://access.redhat.com/errata/RHSA-2026:44481'
  - url: 'https://access.redhat.com/errata/RHSA-2026:58981'
  - url: >-
      https://cgit.git.savannah.nongnu.org/cgit/acl.git/commit/?id=3589787cd589b34bdd9265936e17190b6d3f17d1
  - url: >-
      https://cgit.git.savannah.nongnu.org/cgit/acl.git/commit/?id=24a227d0ab8576612194f8a56c2314389adc74a5
  - url: >-
      https://www.vulncheck.com/advisories/acl-symlink-traversal-privilege-escalation-via-libacl-functions
tags:
  - csaf
  - vex
  - red-hat
  - cve.org
epss: 0.00188
epssPercentile: 0.07488
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: total
  timestamp: '2026-06-29T13:56:13.338794Z'
ingestedAt: '2026-09-14T15:23:07.437Z'
---

## Overview

A flaw was found in the `acl` package, specifically within its `libacl` pathname-based functions. A local attacker could exploit this vulnerability by using a symbolic link to replace a pathname component. This could allow the attacker to redirect access control list (ACL) read or write operations to arbitrary files or directories, leading to unauthorized manipulation of ACLs and ultimately local privilege escalation.

## Vendor advisories

- **RHSA-2026:54769** · Red Hat · fixed in: Red Hat OpenShift Container Platform 4.22 · released 2026-08-18 · [advisory](https://access.redhat.com/errata/RHSA-2026:54769)
- **RHSA-2026:64805** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream EUS (v. 10.0), Red Hat Enterprise Linux BaseOS EUS (v. 10.0) · released 2026-09-08 · [advisory](https://access.redhat.com/errata/RHSA-2026:64805)
- **RHSA-2026:42739** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream (v. 10), Red Hat Enterprise Linux BaseOS (v. 10) · released 2026-07-21 · [advisory](https://access.redhat.com/errata/RHSA-2026:42739)
- **RHSA-2026:67142** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream E4S (v.9.2), Red Hat Enterprise Linux BaseOS E4S (v.9.2) · released 2026-09-14 · [advisory](https://access.redhat.com/errata/RHSA-2026:67142)
- **RHSA-2026:67144** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream E4S (v.9.4), Red Hat Enterprise Linux BaseOS E4S (v.9.4) · released 2026-09-14 · [advisory](https://access.redhat.com/errata/RHSA-2026:67144)
- **RHSA-2026:67140** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream EUS (v.9.6), Red Hat Enterprise Linux BaseOS EUS (v.9.6) · released 2026-09-14 · [advisory](https://access.redhat.com/errata/RHSA-2026:67140)
- **RHSA-2026:42736** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream (v. 9), Red Hat Enterprise Linux BaseOS (v. 9) · released 2026-07-21 · [advisory](https://access.redhat.com/errata/RHSA-2026:42736)
- **RHSA-2026:43420** · Red Hat · fixed in: Red Hat Enterprise Linux BaseOS (v. 8) · released 2026-07-22 · [advisory](https://access.redhat.com/errata/RHSA-2026:43420)
- **RHSA-2026:71656** · Red Hat · fixed in: Red Hat Enterprise Linux BaseOS E4S (v.8.8), Red Hat Enterprise Linux BaseOS TUS (v.8.8) · released 2026-09-24 · [advisory](https://access.redhat.com/errata/RHSA-2026:71656)
- **RHSA-2026:46836** · Red Hat · fixed in: Red Hat Discovery 2 · released 2026-07-27 · [advisory](https://access.redhat.com/errata/RHSA-2026:46836)
- **RHSA-2026:34351** · Red Hat · fixed in: Red Hat Hardened Images · released 2026-07-01 · [advisory](https://access.redhat.com/errata/RHSA-2026:34351)
- **Red Hat VEX** · Important · affected: Red Hat Enterprise Linux 6, Red Hat Enterprise Linux 7, Red Hat OpenShift Container Platform 4 · no fix planned: Red Hat Enterprise Linux 6, Red Hat Enterprise Linux 7, Red Hat OpenShift Container Platform 4 · updated 2026-09-24 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-54369.json)

**acl: Symlink traversal privilege escalation via libacl functions** — rated Important by Red Hat. Released 2026-06-29, updated 2026-09-24.

Affected:

- Red Hat Enterprise Linux 6
- Red Hat Enterprise Linux 7
- Red Hat OpenShift Container Platform 4

Fixed:

- Red Hat OpenShift Container Platform 4.22
- Red Hat Enterprise Linux AppStream EUS (v. 10.0)
- Red Hat Enterprise Linux AppStream (v. 10)
- Red Hat Enterprise Linux AppStream E4S (v.9.2)
- Red Hat Enterprise Linux AppStream E4S (v.9.4)
- Red Hat Enterprise Linux AppStream EUS (v.9.6)
- Red Hat Enterprise Linux AppStream (v. 9)
- Red Hat Enterprise Linux BaseOS EUS (v. 10.0)
- Red Hat Enterprise Linux BaseOS (v. 10)
- Red Hat Enterprise Linux BaseOS (v. 8)
- Red Hat Enterprise Linux BaseOS E4S (v.8.8)
- Red Hat Enterprise Linux BaseOS TUS (v.8.8)
- Red Hat Enterprise Linux BaseOS E4S (v.9.2)
- Red Hat Enterprise Linux BaseOS E4S (v.9.4)
- Red Hat Enterprise Linux BaseOS EUS (v.9.6)
- Red Hat Enterprise Linux BaseOS (v. 9)
- Red Hat Discovery 2
- Red Hat Hardened Images
- Red Hat Insights proxy 1.5
- Red Hat OpenShift distributed tracing 3.10.2
- Red Hat Update Infrastructure 5

No fix planned:

- Red Hat Enterprise Linux 6
- Red Hat Enterprise Linux 7
- Red Hat OpenShift Container Platform 4

Not affected:

- Red Hat Enterprise Linux AppStream EUS (v. 10.0)
- Red Hat Enterprise Linux AppStream (v. 10)
- Red Hat Enterprise Linux AppStream E4S (v.9.2)
- Red Hat Enterprise Linux AppStream E4S (v.9.4)
- Red Hat Enterprise Linux AppStream EUS (v.9.6)
- Red Hat Enterprise Linux AppStream (v. 9)
- Red Hat Enterprise Linux BaseOS EUS (v. 10.0)
- Red Hat Enterprise Linux BaseOS (v. 10)
- Red Hat Enterprise Linux BaseOS (v. 8)
- Red Hat Enterprise Linux BaseOS E4S (v.9.2)

## Remediation

For OpenShift Container Platform 4.22 see the following documentation,
which will be updated shortly for this release, for important instructions
on how to upgrade your cluster and fully apply this asynchronous errata
update:

https://docs.redhat.com/en/documentation/openshift_container_platform/4.22/html/release_notes/

You may download the oc tool and use it to inspect release image metadata
for x86_64, s390x, ppc64le, and aarch64 architectures. The image digests
may be found at
https://quay.io/repository/openshift-release-dev/ocp-release?tab=tags.

The sha values for the release are as fol… https://access.redhat.com/errata/RHSA-2026:54769
For details on how to apply this update, which includes the changes described in this advisory, refer to:

https://access.redhat.com/articles/11258 https://access.redhat.com/errata/RHSA-2026:64805
For details on how to apply this update, which includes the changes described in this advisory, refer to:

https://access.redhat.com/articles/11258 https://access.redhat.com/errata/RHSA-2026:42739

Workarounds / mitigations:

- Restrict unprivileged users from creating symlinks in directories that privileged processes operate on with ACL commands. Where possible, use the fs.protected_symlinks sysctl (enabled by default on RHEL 7+), which prevents symlink following in world-writable sticky directories unless the owner of the symlink matches the owner of the target file or directory.
