Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×

Alerts This Week
Warning Icon 1 464
Alerts This Week
Warning Icon 1 464

Rocky Linux 8 acl Important Symlink Escalation RLSA-2026-43420

rocky
Calendar Grey July 23, 2026
Scroller Rockylinux
An important acl security update for Rocky Linux 8 addresses access control weaknesses that could lead to privilege escalation.
A security update for acl on Rocky Linux 8 addresses vulnerabilities related to privilege escalation and symlink traversal, with CVE scores indicating significant risk levels.

Summary

An update is available for acl. This update affects Rocky Linux 8. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE list


RPMs

acl-0:2.4.0-1.el8_10.aarch64.rpm

acl-0:2.4.0-1.el8_10.src.rpm

acl-0:2.4.0-1.el8_10.x86_64.rpm

acl-debuginfo-0:2.4.0-1.el8_10.aarch64.rpm

acl-debuginfo-0:2.4.0-1.el8_10.i686.rpm

acl-debuginfo-0:2.4.0-1.el8_10.x86_64.rpm

acl-debugsource-0:2.4.0-1.el8_10.aarch64.rpm

acl-debugsource-0:2.4.0-1.el8_10.i686.rpm

acl-debugsource-0:2.4.0-1.el8_10.x86_64.rpm

libacl-0:2.4.0-1.el8_10.aarch64.rpm

libacl-0:2.4.0-1.el8_10.i686.rpm

libacl-0:2.4.0-1.el8_10.x86_64.rpm

libacl-debuginfo-0:2.4.0-1.el8_10.aarch64.rpm

libacl-debuginfo-0:2.4.0-1.el8_10.i686.rpm

libacl-debuginfo-0:2.4.0-1.el8_10.x86_64.rpm

libacl-devel-0:2.4.0-1.el8_10.aarch64.rpm

libacl-devel-0:2.4.0-1.el8_10.i686.rpm

libacl-devel-0:2.4.0-1.el8_10.x86_64.rpm

References

No references

CVES

https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-54369

https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-54370

Severity
important
Lowest
Low
Medium
High
Critical

Name: RLSA-2026:43420
Affected Products: Rocky Linux 8

Fixes

https://bugzilla.redhat.com/show_bug.cgi?id=2490277

https://bugzilla.redhat.com/show_bug.cgi?id=2490279


Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.