<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 19:33:43 +0000</lastBuildDate>
    <item>
      <title>ALSA-2026:56133 — Moderate: attr security update</title>
      <link>https://cve.radiocsirt.org/vuln/alsa-2026:56133</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:8: attr, AlmaLinux:8: libattr, AlmaLinux:8: libattr-devel&lt;/p&gt;
&lt;p&gt;The attr packages provide extended attributes, which can be used to store system objects like capabilities of executables and access control lists, as well as user objects.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* attr: Symlink Traversal Privilege Escalation via getfattr and setfattr (CVE-2026-54371)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:8: attr, AlmaLinux:8: libattr, AlmaLinux:8: libattr-devel&lt;/p&gt;
&lt;p&gt;The attr packages provide extended attributes, which can be used to store system objects like capabilities of executables and access control lists, as well as user objects.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* attr: Symlink Traversal Privilege Escalation via getfattr and setfattr (CVE-2026-54371)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/alsa-2026:56133</guid>
    </item>
    <item>
      <title>certfr-2026-avi-1249 — De multiples vulnérabilités ont été découvertes dans les produits VMware. Elles permettent à un attaquant de provoquer…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2026-avi-1249</link>
      <description>certfr-2026-avi-1249</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2026-avi-1249</guid>
    </item>
    <item>
      <title>EUVD-2026-366750</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-366750</link>
      <description>EUVD-2026-366750</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-366750</guid>
    </item>
    <item>
      <title>fkie_cve-2026-54371</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-54371</link>
      <description>&lt;p&gt;attr before version 2.6.0 contains a symlink traversal vulnerability in the getfattr and setfattr utilities that allows local attackers to escalate privileges by replacing a pathname component with a symbolic link during directory hierarchy traversal. Attackers who control a pathname component can redirect getfattr and setfattr operations to arbitrary files by substituting a symlink, leading to local privilege escalation when getfattr or setfattr is invoked by a privileged process over an attacker-controlled path.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;attr before version 2.6.0 contains a symlink traversal vulnerability in the getfattr and setfattr utilities that allows local attackers to escalate privileges by replacing a pathname component with a symbolic link during directory hierarchy traversal. Attackers who control a pathname component can redirect getfattr and setfattr operations to arbitrary files by substituting a symlink, leading to local privilege escalation when getfattr or setfattr is invoked by a privileged process over an attacker-controlled path.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-54371</guid>
    </item>
    <item>
      <title>GHSA-hh95-r7mj-c9j5</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-hh95-r7mj-c9j5</link>
      <description>&lt;p&gt;attr before version 2.6.0 contains a symlink traversal vulnerability in the getfattr and setfattr utilities that allows local attackers to escalate privileges by replacing a pathname component with a symbolic link during directory hierarchy traversal. Attackers who control a pathname component can redirect getfattr and setfattr operations to arbitrary files by substituting a symlink, leading to local privilege escalation when getfattr or setfattr is invoked by a privileged process over an attacker-controlled path.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;attr before version 2.6.0 contains a symlink traversal vulnerability in the getfattr and setfattr utilities that allows local attackers to escalate privileges by replacing a pathname component with a symbolic link during directory hierarchy traversal. Attackers who control a pathname component can redirect getfattr and setfattr operations to arbitrary files by substituting a symlink, leading to local privilege escalation when getfattr or setfattr is invoked by a privileged process over an attacker-controlled path.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-hh95-r7mj-c9j5</guid>
    </item>
    <item>
      <title>msrc_CVE-2026-54371 — attr &lt; 2.6.0 Symlink Traversal Privilege Escalation via getfattr/setfattr</title>
      <link>https://cve.radiocsirt.org/vuln/msrc_cve-2026-54371</link>
      <description>msrc_CVE-2026-54371</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/msrc_cve-2026-54371</guid>
    </item>
    <item>
      <title>OESA-2026-2913 — attr security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2026-2913</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:24.03-LTS-SP1: attr&lt;/p&gt;
&lt;p&gt;A set of tools for manipulating extended attributes on file system objects, in particular getfattr(1) and setfattr(1). An attr(1) command is also provided, which is largely compatible with the SGI IRIX tool of the same name.&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;attr before version 2.6.0 contains a symlink traversal vulnerability in the getfattr and setfattr utilities that allows local attackers to escalate privileges by replacing a pathname component with a symbolic link during directory hierarchy traversal. Attackers who control a pathname component can redirect getfattr and setfattr operations to arbitrary files by substituting a symlink, leading to local privilege escalation when getfattr or setfattr is invoked by a privileged process over an attacker-controlled path.(CVE-2026-54371)&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:24.03-LTS-SP1: attr&lt;/p&gt;
&lt;p&gt;A set of tools for manipulating extended attributes on file system objects, in particular getfattr(1) and setfattr(1). An attr(1) command is also provided, which is largely compatible with the SGI IRIX tool of the same name.&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;attr before version 2.6.0 contains a symlink traversal vulnerability in the getfattr and setfattr utilities that allows local attackers to escalate privileges by replacing a pathname component with a symbolic link during directory hierarchy traversal. Attackers who control a pathname component can redirect getfattr and setfattr operations to arbitrary files by substituting a symlink, leading to local privilege escalation when getfattr or setfattr is invoked by a privileged process over an attacker-controlled path.(CVE-2026-54371)&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2026-2913</guid>
    </item>
    <item>
      <title>openSUSE-SU-2026:11312-1 — acl-2.4.0-1.1 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2026:11312-1</link>
      <description>&lt;p&gt;acl-2.4.0-1.1 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;acl-2.4.0-1.1 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2026:11312-1</guid>
    </item>
    <item>
      <title>RHSA-2026:34889 — Red Hat Security Advisory: Red Hat Hardened Images RPMs Security Update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2026:34889</link>
      <description>&lt;p&gt;attr: attr: Symlink Traversal Privilege Escalation via getfattr and setfattr&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;attr: attr: Symlink Traversal Privilege Escalation via getfattr and setfattr&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2026:34889</guid>
    </item>
    <item>
      <title>RLSA-2026:56133 — Moderate: attr security update</title>
      <link>https://cve.radiocsirt.org/vuln/rlsa-2026:56133</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Rocky Linux:8: attr&lt;/p&gt;
&lt;p&gt;The attr packages provide extended attributes, which can be used to store system objects like capabilities of executables and access control lists, as well as user objects.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* attr: Symlink Traversal Privilege Escalation via getfattr and setfattr (CVE-2026-54371)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Rocky Linux:8: attr&lt;/p&gt;
&lt;p&gt;The attr packages provide extended attributes, which can be used to store system objects like capabilities of executables and access control lists, as well as user objects.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* attr: Symlink Traversal Privilege Escalation via getfattr and setfattr (CVE-2026-54371)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rlsa-2026:56133</guid>
    </item>
    <item>
      <title>SUSE-SU-2026:23670-1 — Security update for acl, attr</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2026:23670-1</link>
      <description>&lt;p&gt;Security update for acl, attr&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for acl, attr&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2026:23670-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2026-54371</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-54371</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: attr, Ubuntu:Pro:16.04:LTS: attr, Ubuntu:Pro:18.04:LTS: attr, Ubuntu:Pro:20.04:LTS: attr, Ubuntu:22.04:LTS: attr, Ubuntu:24.04:LTS: attr, Ubuntu:25.10: attr, Ubuntu:26.04:LTS: attr&lt;/p&gt;
&lt;p&gt;attr before version 2.6.0 contains a symlink traversal vulnerability in the getfattr and setfattr utilities that allows local attackers to escalate privileges by replacing a pathname component with a symbolic link during directory hierarchy traversal. Attackers who control a pathname component can redirect getfattr and setfattr operations to arbitrary files by substituting a symlink, leading to local privilege escalation when getfattr or setfattr is invoked by a privileged process over an attacker-controlled path.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: attr, Ubuntu:Pro:16.04:LTS: attr, Ubuntu:Pro:18.04:LTS: attr, Ubuntu:Pro:20.04:LTS: attr, Ubuntu:22.04:LTS: attr, Ubuntu:24.04:LTS: attr, Ubuntu:25.10: attr, Ubuntu:26.04:LTS: attr&lt;/p&gt;
&lt;p&gt;attr before version 2.6.0 contains a symlink traversal vulnerability in the getfattr and setfattr utilities that allows local attackers to escalate privileges by replacing a pathname component with a symbolic link during directory hierarchy traversal. Attackers who control a pathname component can redirect getfattr and setfattr operations to arbitrary files by substituting a symlink, leading to local privilege escalation when getfattr or setfattr is invoked by a privileged process over an attacker-controlled path.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-54371</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-2920 — Red Hat Enterprise Linux (attr): Schwachstelle ermöglicht Privilegieneskalation</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2920</link>
      <description>&lt;p&gt;Ein lokaler Angreifer kann eine Schwachstelle in Red Hat Enterprise Linux (attr) ausnutzen, um seine Privilegien zu erhöhen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein lokaler Angreifer kann eine Schwachstelle in Red Hat Enterprise Linux (attr) ausnutzen, um seine Privilegien zu erhöhen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2920</guid>
    </item>
  </channel>
</rss>
