[ GLSA 202608-20 ] acl, attr: Multiple vulnerabilities

[email protected]
Newsgroups gmane.linux.gentoo.announce
Message-ID <178719946412.1.7846522666015769818@f5bc8f6d682b>
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
Gentoo Linux Security Advisory                           GLSA 202608-20
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
                                           https://security.gentoo.org/
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -

 Severity: High
    Title: acl, attr: Multiple vulnerabilities
     Date: August 20, 2026
     Bugs: #978280
       ID: 202608-20

- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -

Synopsis
========

Multiple vulnerabilities have been found in acl and attr, the worst of
which could lead to local privilege escalation.

Background
==========

For more information on the packages listed in this GLSA, please see
their homepage referenced in the ebuild.

Affected packages
=================

Package        Vulnerable    Unaffected
-------------  ------------  ------------
sys-apps/acl   < 2.4.0       >= 2.4.0
sys-apps/attr  < 2.6.0       >= 2.6.0

Description
===========

Multiple vulnerabilities have been discovered in acl and attr. Please
review the CVE identifiers referenced below for details.

Impact
======

Please review the referenced CVE identifiers for details.

Workaround
==========

There is no known workaround at this time.

Resolution
==========

All acl users should upgrade to the latest version:

  # emerge --sync
  # emerge --ask --oneshot --verbose ">=sys-apps/acl-2.4.0"

All attr users should upgrade to the latest version:

  # emerge --sync
  # emerge --ask --oneshot --verbose ">=sys-apps/attr-2.6.0"

References
==========

[ 1 ] CVE-2026-54369
      https://nvd.nist.gov/vuln/detail/CVE-2026-54369
[ 2 ] CVE-2026-54370
      https://nvd.nist.gov/vuln/detail/CVE-2026-54370
[ 3 ] CVE-2026-54371
      https://nvd.nist.gov/vuln/detail/CVE-2026-54371

Availability
============

This GLSA and any updates to it are available for viewing at
the Gentoo Security Website:

 https://security.gentoo.org/glsa/202608-20

Concerns?
=========

Security is a primary focus of Gentoo Linux and ensuring the
confidentiality and security of our users' machines is of utmost
importance to us. Any security concerns should be addressed to
[email protected] or alternatively, you may file a bug at
https://bugs.gentoo.org.

License
=======

Copyright 2026 Gentoo Foundation, Inc; referenced text
belongs to its owner(s).

The contents of this document are licensed under the
Creative Commons - Attribution / Share Alike license.

https://creativecommons.org/licenses/by-sa/2.5
signature.asc (application/pgp-signature, 870 B)
-----BEGIN PGP SIGNATURE-----

iQJPBAEBCAA5FiEEpqTA6ABLMxh/aChGFMQkOaVy+9kFAmqGf+cbFIAAAAAABAAO
bWFudTIsMi41KzEuMTIsMiwyAAoJEBTEJDmlcvvZ4hUP/2GkEJ5vuGI3l+jlPIfi
YnZMHU9fOJxGWNoHcUCJ30wW80iaVLFZpcecgpyqg7Ci0z5fhZL1N1cMGbm5r4Md
p/8pe3Ub43r5e2NaVW/yQ3VufKeMs3cBt8jXlmpqgZ0yjM3k1OYYRMi59qgIISUI
GPWkHCcqVH5koHS9U4za9MfeFgaqljW+iwZi3eDvhLccmuNmJrB7v00CfWGMSMUv
jwK7koSUfvC5CRHu9ES+PwwiWrSDSVPEwAivdmQS+BXYbKes9GTril20UiBUbQuB
/0BFKD+8eGz/xyzpoCmn0yNp3Z/yoXzgi8Mtcnlm/HkGmKjH7c63FO8yktxwnXL2
4OGD/Aor8YfO/8DsO1J8xWILcuXzqRhHReSw4WvJ0NFLVp09V/kv/SqWvI6dI2do
M2Jy9AzXP1yKuu663rZrW8g+sZMeu8gU5dCZAq2xc0pYJ6jSqvs5goCn0c1c9Gx4
e1ItznXwLR4C/zoaqWCZwUIlFvy/5CnlSOM6CEtrBeONXPitCe7Bb1U3nBfZXD8s
nr3hhKIq6cApm+fYJiJA3i0EnUZi3nuKSsTlStlEbFNb0UEwglVUTBBtYQK6LGzd
OeRksWm2kFkGH2dcpi2W/bAHPV1vp5x9uQ9pplt9V+jX1SD/6iW+3RB9s80i994s
XKM7XFVv5TVFFL3u3nRWlPqO
=uYK2
-----END PGP SIGNATURE-----
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.