[CLSA-2026:1785347213] attr: Fix of CVE-2026-54371
Type:
security
Severity:
Moderate
Release date:
2026-07-29 17:47:02 UTC
Description:
- CVE-2026-54371: symlink traversal in the recursive directory walk of getfattr, letting a local attacker who controls a path component swap it for a symlink and redirect extended-attribute reads to arbitrary files
CVEs fixed:
Updated packages:
  • attr-2.4.48-3.el8.tuxcare.els1.x86_64.rpm
    sha:a49daed5f2b7c2eb67de9ed5b93660ca593263ae8dfeaa9da69bf4318115f4b7
  • libattr-2.4.48-3.el8.tuxcare.els1.i686.rpm
    sha:26e31fe0d5ab558103d6b5659d5c1f8ba98313ba10b0d313a57311f40b103492
  • libattr-2.4.48-3.el8.tuxcare.els1.x86_64.rpm
    sha:d98ef5e81015664ec6acac67b6d9a9784deda4fc9f13e015eb122addf1b191a5
  • libattr-devel-2.4.48-3.el8.tuxcare.els1.i686.rpm
    sha:dff0889306497ad34ae1d1004d3f32b12b4162c03ac609a22955e09cf86448a9
  • libattr-devel-2.4.48-3.el8.tuxcare.els1.x86_64.rpm
    sha:e392a279359ef4ba8a856a8d07855bfc33c7bda664811ef9ac62cdd7ed89c650
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.