THREATOPS
THREAT OPSThreat News › [NVD] CVE-2026-54371 (HIGH 7.1) — attr before version 2.6.0 contains a symlink traversal vulnerability in the getfattr and setfattr utilities that allows local attackers to escalate privileges by replacing a pathname component with a symbolic link during directory hierarchy traversal. Attackers who control a path

[NVD] CVE-2026-54371 (HIGH 7.1) — attr before version 2.6.0 contains a symlink traversal vulnerability in the getfattr and setfattr utilities that allows local attackers to escalate privileges by replacing a pathname component with a symbolic link during directory hierarchy traversal. Attackers who control a path

lownvdPublished 2026-06-29

CVE-2026-54371 CVSS: 7.1 HIGH Published: 2026-06-29T14:16:57.823

attr before version 2.6.0 contains a symlink traversal vulnerability in the getfattr and setfattr utilities that allows local attackers to escalate privileges by replacing a pathname component with a symbolic link during directory hierarchy traversal. Attackers who control a pathname component can redirect getfattr and setfattr oper

Indicators of compromise

Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-54371