Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×

Alerts This Week
Warning Icon 1 471
Alerts This Week
Warning Icon 1 471

Oracle Linux 10 Faces Major Vulnerability with Symlink Escalation Risk

oracle
Calendar Grey July 22, 2026
Scroller Oracle
Critical updates for Oracle Linux 10 address important symlink privilege escalation issues. Immediate action recommended.
Oracle Linux has released updated RPMs for version 10, addressing privilege escalation vulnerabilities (CVE-2026-54369 and CVE-2026-54370) in the acl package.

Summary

[2.4.0-1] - rebase to 2.4.0 to fix the following CVEs: - CVE-2026-54369 - Symlink traversal privilege escalation via libacl functions (RHEL-186106) - CVE-2026-54370 - TOCTOU Symlink Traversal via getfacl/setfacl (RHEL-186207)

SRPMs

http://oss.oracle.com/ol10/SRPMS-updates/acl-2.4.0-1.el10_2.src.rpm

x86_64

acl-2.4.0-1.el10_2.x86_64.rpm libacl-2.4.0-1.el10_2.x86_64.rpm libacl-devel-2.4.0-1.el10_2.x86_64.rpm

aarch64

acl-2.4.0-1.el10_2.aarch64.rpm libacl-2.4.0-1.el10_2.aarch64.rpm libacl-devel-2.4.0-1.el10_2.aarch64.rpm

Severity
important
Lowest
Low
Medium
High
Critical

Related CVEs: CVE-2026-54369 CVE-2026-54370

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.