Multiple vulnerabilities have been found in acl and attr, the worst of which could lead to local privilege escalation. Affected packages Package sys-apps/acl on all architectures Affected versions < 2.4.0 Unaffected versions >= 2.4.0 Package sys-apps/attr on all architectures Affected versions < 2.6.0 Unaffected versions >= 2.6.0 Background For more information on the packages listed in this GLSA, please see their homepage referenced in the ebuild. Description Multiple vulnerabilities have been discovered in acl and attr. Please review the CVE identifiers referenced below for details. Impact Please review the referenced CVE identifiers for details. Workaround There is no known workaround at this time. Resolution All acl users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose ">=sys-apps/acl-2.4.0" All attr users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose ">=sys-apps/attr-2.6.0" References CVE-2026-54369 CVE-2026-54370 CVE-2026-54371 Release date August 20, 2026 Latest revision August 20, 2026: 1 Severity high Exploitable local Bugzilla entries 978280
Multiple vulnerabilities in the `acl` and `attr` utilities (CVE-2026-54369, CVE-2026-54370, CVE-2026-54371) include high-severity issues (CVSS up to 7.1) that could lead to local privilege escalation. Affected versions are `sys-apps/acl` prior to version 2.4.0 and `sys-apps/attr` prior to version 2.6.0. The resolution is to upgrade to `acl` version 2.4.0 and `attr` version 2.6.0, as no workaround is currently available.