RHSA-2026:56133: Moderate: attr security update
Moderate: attr security update
Other sources
The attr packages provide extended attributes, which can be used to store system objects like capabilities of executables and access control lists, as well as user objects.Security Fix(es): attr: Symlink Traversal Privilege Escalation via getfattr and setfattr (CVE-2026-54371) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
— Red Hat
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/attrto a version that resolves this vulnerability.Fixed in 2.6.0-1.el8_10 - Upgrade
Upgrade
redhat/attr-debuginfoto a version that resolves this vulnerability.Fixed in 2.6.0-1.el8_10 - Upgrade
Upgrade
redhat/attr-debugsourceto a version that resolves this vulnerability.Fixed in 2.6.0-1.el8_10 - Upgrade
Upgrade
redhat/libattrto a version that resolves this vulnerability.Fixed in 2.6.0-1.el8_10 - Upgrade
Upgrade
redhat/libattr-debuginfoto a version that resolves this vulnerability.Fixed in 2.6.0-1.el8_10 - Upgrade
Upgrade
redhat/libattr-develto a version that resolves this vulnerability.Fixed in 2.6.0-1.el8_10 - Upgrade
Upgrade
redhat/attrto a version that resolves this vulnerability.Fixed in 2.6.0-1.el8_10.aa - Upgrade
Upgrade
redhat/attr-debuginfoto a version that resolves this vulnerability.Fixed in 2.6.0-1.el8_10.aa - Upgrade
Upgrade
redhat/attr-debugsourceto a version that resolves this vulnerability.Fixed in 2.6.0-1.el8_10.aa - Upgrade
Upgrade
redhat/libattrto a version that resolves this vulnerability.Fixed in 2.6.0-1.el8_10.aa - Upgrade
Upgrade
redhat/libattr-debuginfoto a version that resolves this vulnerability.Fixed in 2.6.0-1.el8_10.aa - Upgrade
Upgrade
redhat/libattr-develto a version that resolves this vulnerability.Fixed in 2.6.0-1.el8_10.aa - Upgrade
Upgrade
attrto a version that resolves this vulnerability.Patch CVE-2026-54371
Event History
Frequently Asked Questions
Which systems and packages are covered by this advisory?
Systems using the affected attr packages on Red Hat Enterprise Linux for ARM 64 or x86_64 Extended Life Cycle are in scope. The listed packages include attr, libattr, development packages, and associated debug packages.
What is known about exploitation conditions?
The issue is described as a symlink traversal privilege escalation involving the getfattr and setfattr utilities. The provided information does not state the required attacker access level, affected configuration conditions, or whether default installations are vulnerable.
What should administrators do to remediate the issue?
Apply the RHSA-2026:56133 security update for the applicable Red Hat Enterprise Linux Extended Life Cycle platform. The provided information does not include a workaround or mitigation for systems that cannot be patched immediately.