THREAT OPS › Threat News › [NVD] CVE-2026-54371 (HIGH 7.1) — attr before version 2.6.0 contains a symlink traversal vulnerability in the getfattr and setfattr utilities that allows local attackers to escalate privileges by replacing a pathname component with a symbolic link during directory hierarchy traversal. Attackers who control a path
[NVD] CVE-2026-54371 (HIGH 7.1) — attr before version 2.6.0 contains a symlink traversal vulnerability in the getfattr and setfattr utilities that allows local attackers to escalate privileges by replacing a pathname component with a symbolic link during directory hierarchy traversal. Attackers who control a path
CVE-2026-54371 CVSS: 7.1 HIGH Published: 2026-06-29T14:16:57.823
attr before version 2.6.0 contains a symlink traversal vulnerability in the getfattr and setfattr utilities that allows local attackers to escalate privileges by replacing a pathname component with a symbolic link during directory hierarchy traversal. Attackers who control a pathname component can redirect getfattr and setfattr oper
Indicators of compromise
- CVE-2026-54371cve
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-54371