attr before version 2.6.0 contains a symlink traversal vulnerability in the getfattr and setfattr utilities that allows local attackers to escalate privileges by replacing a pathname component with a symbolic link during directory hierarchy traversal. Attackers who control a pathname component can redirect getfattr and setfattr operations to arbitrary files by substituting a symlink, leading to local privilege escalation when getfattr or setfattr is invoked by a privileged process over an attacker-controlled path.
| Vendor | Product | Versions |
|---|---|---|
| gnu | attr | 0 |
Downstream vendors/products affected by this vulnerability
| Vendor | Product | Source | Confidence |
|---|---|---|---|
| red hat | red hat enterprise linux | cert_advisory | 90% |
| resf | resf rocky linux | cert_advisory | 90% |
Added CWE-367, updated patch availability to acl-2.4.0 and attr-2.6.0, and included additional CVE tags.
Updated severity to CRITICAL, noted no exploit available, and added new CVE ID.
Initial creation