Linuxsecurity Critical Symlink Traversal Vulnerabilities in Fedora 44 Affected by CVEs
Article Content
- •Fedora 44 acl and attr packages have critical symlink traversal vulnerabilities.
- •Three CVEs (CVE-2026-54369, CVE-2026-54370, CVE-2026-54371) were published on June 29, 2026.
- •Users are urged to apply updates immediately to mitigate privilege escalation risks.
On July 9, 2026, Fedora released updates addressing critical symlink traversal vulnerabilities in its acl and attr packages. The vulnerabilities, identified as CVE-2026-54369, CVE-2026-54370, and CVE-2026-54371, were published on June 29, 2026. CVE-2026-54369 and CVE-2026-54370 involve privilege escalation via libacl functions and TOCTOU symlink traversal through getfacl/setfacl. CVE-2026-54371 also presents a privilege escalation risk via getfattr. These vulnerabilities could allow attackers to gain elevated privileges on affected systems. Users are advised to upgrade to the latest versions using the provided dnf commands. The updates are critical for maintaining system security against potential exploitation.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (7)
Following this threat?
Track Fedora and CVE-2026-54369 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
SUSE acl Vulnerabilities Allow Local Privilege Escalation SUSE has released updates addressing critical vulnerabilities in the acl and attr packages, specifically CVE-2026-54369, CVE-2026-54370, and CVE-2026-54371. These vulnerabilities allow attackers to exploit symlink traversal issues in libacl functions, potentially leading to local privilege escalation. The affected…
CVE-2015-3306 Exploited in ProFTPD FTP Servers CVE-2015-3306, a vulnerability in ProFTPD 1.3.5, allows remote attackers to read and write arbitrary files using the SITE CPFR and SITE CPTO commands. This exploit can lead to unauthorized access and potential remote code execution, as the commands are executed with the privileges of the ProFTPD service. Active…