Executive brief
A vulnerability in the standard Linux Access Control List (ACL) library could allow a local user to gain elevated system privileges. By tricking a high-privilege program into following a specially crafted file shortcut (symbolic link), an attacker can modify the security settings of sensitive system files. This could lead to unauthorized access to private data or full control over the affected system.
Technical details
A symlink traversal vulnerability (CWE-59) exists in libacl's pathname-based functions, including acl_get_file(), acl_set_file(), acl_extended_file(), and acl_delete_def_file(). The root cause is improper link resolution before file access, allowing a local attacker to replace a component of a pathname with a symbolic link. If a privileged process calls these functions on a path controlled by an attacker, the attacker can redirect ACL operations to arbitrary files. This enables unauthorized modification of file permissions and local privilege escalation. The issue is addressed in version 2.4.0.
Affected products
- acl project acl < 2.4.0
Timeline
- 2026-06-29: disclosed
- 2026-06-29: advisory
References
- https://cgit.git.savannah.nongnu.org/cgit/acl.git/commit/?id=24a227d0ab8576612194f8a56c2314389adc74a5
- https://cgit.git.savannah.nongnu.org/cgit/acl.git/commit/?id=3589787cd589b34bdd9265936e17190b6d3f17d1
- https://www.vulncheck.com/advisories/acl-symlink-traversal-privilege-escalation-via-libacl-functions