Skip to content
SUSE acl Vulnerabilities Allow Local Privilege Escalation

SUSE acl Vulnerabilities Allow Local Privilege Escalation

First seen 15 Sep 2026, 10:53 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster September 15, 2026 at 11:56 UTC

SUSE has released updates addressing critical vulnerabilities in the acl and attr packages, specifically CVE-2026-54369, CVE-2026-54370, and CVE-2026-54371. These vulnerabilities allow attackers to exploit symlink traversal issues in libacl functions, potentially leading to local privilege escalation. The affected functions include acl_get_file(), acl_set_file(), acl_extended_file(), and acl_delete_def_file(), which follow symbolic links and can be manipulated by an attacker controlling a pathname component. The vulnerabilities were published on June 29, 2026, and have been rated as important. Users are urged to update to version 2.4.0 to mitigate these risks. The updates were released on September 11 and September 14, 2026, with the latest advisory published on September 15, 2026. The vulnerabilities affect systems running SUSE 15 SP7 and other distributions utilizing the affected packages.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2026-06-29
CVE-2026-54369 published
SUSE disclosed a symlink traversal vulnerability in acl and attr packages, allowing local privilege escalation.
Linuxsecurity
2026-06-29
CVE-2026-54370 published
SUSE disclosed a related vulnerability in acl and attr packages, contributing to local privilege escalation risks.
Linuxsecurity
2026-06-29
CVE-2026-54371 published
SUSE disclosed another vulnerability in acl and attr packages, allowing for potential local privilege escalation.
Linuxsecurity
2026-09-11
SUSE releases patch for vulnerabilities
SUSE released updates for acl and attr packages to address the disclosed vulnerabilities, urging users to upgrade.
Linuxsecurity
2026-09-14
Second advisory published
SUSE issued an additional advisory regarding the acl and attr vulnerabilities, emphasizing the need for immediate updates.
Linuxsecurity
2026-09-15
Current advisory status
SUSE continues to urge users to apply the updates to mitigate local privilege escalation risks from the vulnerabilities.
Linuxsecurity

More articles in this cluster (2)

Following this threat?

Track CVE-2026-54369 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed