<?xml version="1.0" encoding="UTF-8"?>
<cvrfdoc xmlns="http://www.icasi.org/CVRF/schema/cvrf/1.1" xmlns:cvrf="http://www.icasi.org/CVRF/schema/cvrf/1.1">
	<DocumentTitle xml:lang="en">An update for acl is now available for openEuler-20.03-LTS-SP4,openEuler-22.03-LTS-SP4,openEuler-24.03-LTS-SP1,openEuler-24.03-LTS-SP3,openEuler-24.03-LTS-SP4</DocumentTitle>
	<DocumentType>Security Advisory</DocumentType>
	<DocumentPublisher Type="Vendor">
		<ContactDetails>openeuler-security@openeuler.org</ContactDetails>
		<IssuingAuthority>openEuler security committee</IssuingAuthority>
	</DocumentPublisher>
	<DocumentTracking>
		<Identification>
			<ID>openEuler-SA-2026-3079</ID>
		</Identification>
		<Status>Final</Status>
		<Version>1.0</Version>
		<RevisionHistory>
			<Revision>
				<Number>1.0</Number>
				<Date>2026-07-19</Date>
				<Description>Initial</Description>
			</Revision>
		</RevisionHistory>
		<InitialReleaseDate>2026-07-19</InitialReleaseDate>
		<CurrentReleaseDate>2026-07-19</CurrentReleaseDate>
		<Generator>
			<Engine>openEuler SA Tool V1.0</Engine>
			<Date>2026-07-19</Date>
		</Generator>
	</DocumentTracking>
	<DocumentNotes>
		<Note Title="Synopsis" Type="General" Ordinal="1" xml:lang="en">acl security update</Note>
		<Note Title="Summary" Type="General" Ordinal="2" xml:lang="en">An update for acl is now available for openEuler-20.03-LTS-SP4,openEuler-22.03-LTS-SP4,openEuler-24.03-LTS-SP1,openEuler-24.03-LTS-SP3,openEuler-24.03-LTS-SP4</Note>
		<Note Title="Description" Type="General" Ordinal="3" xml:lang="en">This package contains commands for manipulating POSIX access control lists, and the libacl.so dynamic library which contains the POSIX 1003.1e draft standard 17 functions for manipulating access control lists.

Security Fix(es):

acl before version 2.4.0 contains a symlink traversal vulnerability in the libacl pathname-based functions acl_get_file(), acl_set_file(), acl_extended_file(), and acl_delete_def_file() that allows local attackers to escalate privileges by replacing any pathname component with a symbolic link. Attackers who control any component of a pathname processed by a privileged caller can redirect ACL read or write operations to arbitrary files or directories, enabling unauthorized manipulation of access control lists and local privilege escalation.(CVE-2026-54369)

acl before version 2.4.0 contains a time-of-check to time-of-use (TOCTOU) race condition vulnerability that allows local attackers to escalate privileges by replacing a pathname component with a symbolic link between an lstat() check and subsequent symlink-following operations such as stat(), chown(), chmod(), acl_get_file(), and acl_set_file(). Attackers who control a pathname component can redirect file access control list operations to arbitrary files when getfacl, setfacl, or chacl is invoked by a privileged process over an attacker-controlled path, resulting in local privilege escalation.(CVE-2026-54370)</Note>
		<Note Title="Topic" Type="General" Ordinal="4" xml:lang="en">An update for acl is now available for openEuler-20.03-LTS-SP4,openEuler-22.03-LTS-SP4,openEuler-24.03-LTS-SP1,openEuler-24.03-LTS-SP3,openEuler-24.03-LTS-SP4.

openEuler Security has rated this update as having a security impact of high. A Common Vunlnerability Scoring System(CVSS)base score,which gives a detailed severity rating, is available for each vulnerability from the CVElink(s) in the References section.</Note>
		<Note Title="Severity" Type="General" Ordinal="5" xml:lang="en">High</Note>
		<Note Title="Affected Component" Type="General" Ordinal="6" xml:lang="en">acl</Note>
	</DocumentNotes>
	<DocumentReferences>
		<Reference Type="Self">
			<URL>https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-3079</URL>
		</Reference>
		<Reference Type="openEuler CVE">
			<URL>https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-54369</URL>
			<URL>https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-54370</URL>
		</Reference>
		<Reference Type="Other">
			<URL>https://nvd.nist.gov/vuln/detail/CVE-2026-54369</URL>
			<URL>https://nvd.nist.gov/vuln/detail/CVE-2026-54370</URL>
		</Reference>
	</DocumentReferences>
	<ProductTree xmlns="http://www.icasi.org/CVRF/schema/prod/1.1">
		<Branch Type="Product Name" Name="openEuler">
			<FullProductName ProductID="openEuler-20.03-LTS-SP4" CPE="cpe:/a:openEuler:openEuler:20.03-LTS-SP4">openEuler-20.03-LTS-SP4</FullProductName>
			<FullProductName ProductID="openEuler-22.03-LTS-SP4" CPE="cpe:/a:openEuler:openEuler:22.03-LTS-SP4">openEuler-22.03-LTS-SP4</FullProductName>
			<FullProductName ProductID="openEuler-24.03-LTS-SP1" CPE="cpe:/a:openEuler:openEuler:24.03-LTS-SP1">openEuler-24.03-LTS-SP1</FullProductName>
			<FullProductName ProductID="openEuler-24.03-LTS-SP3" CPE="cpe:/a:openEuler:openEuler:24.03-LTS-SP3">openEuler-24.03-LTS-SP3</FullProductName>
			<FullProductName ProductID="openEuler-24.03-LTS-SP4" CPE="cpe:/a:openEuler:openEuler:24.03-LTS-SP4">openEuler-24.03-LTS-SP4</FullProductName>
		</Branch>
		<Branch Type="Package Arch" Name="aarch64">
			<FullProductName ProductID="acl-2.2.53-14" CPE="cpe:/a:openEuler:openEuler:20.03-LTS-SP4">acl-2.2.53-14.oe2003sp4.aarch64.rpm</FullProductName>
			<FullProductName ProductID="acl-debuginfo-2.2.53-14" CPE="cpe:/a:openEuler:openEuler:20.03-LTS-SP4">acl-debuginfo-2.2.53-14.oe2003sp4.aarch64.rpm</FullProductName>
			<FullProductName ProductID="acl-debugsource-2.2.53-14" CPE="cpe:/a:openEuler:openEuler:20.03-LTS-SP4">acl-debugsource-2.2.53-14.oe2003sp4.aarch64.rpm</FullProductName>
			<FullProductName ProductID="libacl-2.2.53-14" CPE="cpe:/a:openEuler:openEuler:20.03-LTS-SP4">libacl-2.2.53-14.oe2003sp4.aarch64.rpm</FullProductName>
			<FullProductName ProductID="libacl-devel-2.2.53-14" CPE="cpe:/a:openEuler:openEuler:20.03-LTS-SP4">libacl-devel-2.2.53-14.oe2003sp4.aarch64.rpm</FullProductName>
			<FullProductName ProductID="acl-2.3.1-7" CPE="cpe:/a:openEuler:openEuler:22.03-LTS-SP4">acl-2.3.1-7.oe2203sp4.aarch64.rpm</FullProductName>
			<FullProductName ProductID="acl-debuginfo-2.3.1-7" CPE="cpe:/a:openEuler:openEuler:22.03-LTS-SP4">acl-debuginfo-2.3.1-7.oe2203sp4.aarch64.rpm</FullProductName>
			<FullProductName ProductID="acl-debugsource-2.3.1-7" CPE="cpe:/a:openEuler:openEuler:22.03-LTS-SP4">acl-debugsource-2.3.1-7.oe2203sp4.aarch64.rpm</FullProductName>
			<FullProductName ProductID="libacl-2.3.1-7" CPE="cpe:/a:openEuler:openEuler:22.03-LTS-SP4">libacl-2.3.1-7.oe2203sp4.aarch64.rpm</FullProductName>
			<FullProductName ProductID="libacl-devel-2.3.1-7" CPE="cpe:/a:openEuler:openEuler:22.03-LTS-SP4">libacl-devel-2.3.1-7.oe2203sp4.aarch64.rpm</FullProductName>
			<FullProductName ProductID="acl-2.3.1-7" CPE="cpe:/a:openEuler:openEuler:24.03-LTS-SP1">acl-2.3.1-7.oe2403sp1.aarch64.rpm</FullProductName>
			<FullProductName ProductID="acl-debuginfo-2.3.1-7" CPE="cpe:/a:openEuler:openEuler:24.03-LTS-SP1">acl-debuginfo-2.3.1-7.oe2403sp1.aarch64.rpm</FullProductName>
			<FullProductName ProductID="acl-debugsource-2.3.1-7" CPE="cpe:/a:openEuler:openEuler:24.03-LTS-SP1">acl-debugsource-2.3.1-7.oe2403sp1.aarch64.rpm</FullProductName>
			<FullProductName ProductID="libacl-2.3.1-7" CPE="cpe:/a:openEuler:openEuler:24.03-LTS-SP1">libacl-2.3.1-7.oe2403sp1.aarch64.rpm</FullProductName>
			<FullProductName ProductID="libacl-devel-2.3.1-7" CPE="cpe:/a:openEuler:openEuler:24.03-LTS-SP1">libacl-devel-2.3.1-7.oe2403sp1.aarch64.rpm</FullProductName>
			<FullProductName ProductID="acl-2.3.1-7" CPE="cpe:/a:openEuler:openEuler:24.03-LTS-SP3">acl-2.3.1-7.oe2403sp3.aarch64.rpm</FullProductName>
			<FullProductName ProductID="acl-debuginfo-2.3.1-7" CPE="cpe:/a:openEuler:openEuler:24.03-LTS-SP3">acl-debuginfo-2.3.1-7.oe2403sp3.aarch64.rpm</FullProductName>
			<FullProductName ProductID="acl-debugsource-2.3.1-7" CPE="cpe:/a:openEuler:openEuler:24.03-LTS-SP3">acl-debugsource-2.3.1-7.oe2403sp3.aarch64.rpm</FullProductName>
			<FullProductName ProductID="libacl-2.3.1-7" CPE="cpe:/a:openEuler:openEuler:24.03-LTS-SP3">libacl-2.3.1-7.oe2403sp3.aarch64.rpm</FullProductName>
			<FullProductName ProductID="libacl-devel-2.3.1-7" CPE="cpe:/a:openEuler:openEuler:24.03-LTS-SP3">libacl-devel-2.3.1-7.oe2403sp3.aarch64.rpm</FullProductName>
			<FullProductName ProductID="acl-2.3.1-7" CPE="cpe:/a:openEuler:openEuler:24.03-LTS-SP4">acl-2.3.1-7.oe2403sp4.aarch64.rpm</FullProductName>
			<FullProductName ProductID="acl-debuginfo-2.3.1-7" CPE="cpe:/a:openEuler:openEuler:24.03-LTS-SP4">acl-debuginfo-2.3.1-7.oe2403sp4.aarch64.rpm</FullProductName>
			<FullProductName ProductID="acl-debugsource-2.3.1-7" CPE="cpe:/a:openEuler:openEuler:24.03-LTS-SP4">acl-debugsource-2.3.1-7.oe2403sp4.aarch64.rpm</FullProductName>
			<FullProductName ProductID="libacl-2.3.1-7" CPE="cpe:/a:openEuler:openEuler:24.03-LTS-SP4">libacl-2.3.1-7.oe2403sp4.aarch64.rpm</FullProductName>
			<FullProductName ProductID="libacl-devel-2.3.1-7" CPE="cpe:/a:openEuler:openEuler:24.03-LTS-SP4">libacl-devel-2.3.1-7.oe2403sp4.aarch64.rpm</FullProductName>
		</Branch>
		<Branch Type="Package Arch" Name="src">
			<FullProductName ProductID="acl-2.2.53-14" CPE="cpe:/a:openEuler:openEuler:20.03-LTS-SP4">acl-2.2.53-14.oe2003sp4.src.rpm</FullProductName>
			<FullProductName ProductID="acl-2.3.1-7" CPE="cpe:/a:openEuler:openEuler:22.03-LTS-SP4">acl-2.3.1-7.oe2203sp4.src.rpm</FullProductName>
			<FullProductName ProductID="acl-2.3.1-7" CPE="cpe:/a:openEuler:openEuler:24.03-LTS-SP1">acl-2.3.1-7.oe2403sp1.src.rpm</FullProductName>
			<FullProductName ProductID="acl-2.3.1-7" CPE="cpe:/a:openEuler:openEuler:24.03-LTS-SP3">acl-2.3.1-7.oe2403sp3.src.rpm</FullProductName>
			<FullProductName ProductID="acl-2.3.1-7" CPE="cpe:/a:openEuler:openEuler:24.03-LTS-SP4">acl-2.3.1-7.oe2403sp4.src.rpm</FullProductName>
		</Branch>
		<Branch Type="Package Arch" Name="x86_64">
			<FullProductName ProductID="acl-2.2.53-14" CPE="cpe:/a:openEuler:openEuler:20.03-LTS-SP4">acl-2.2.53-14.oe2003sp4.x86_64.rpm</FullProductName>
			<FullProductName ProductID="acl-debuginfo-2.2.53-14" CPE="cpe:/a:openEuler:openEuler:20.03-LTS-SP4">acl-debuginfo-2.2.53-14.oe2003sp4.x86_64.rpm</FullProductName>
			<FullProductName ProductID="acl-debugsource-2.2.53-14" CPE="cpe:/a:openEuler:openEuler:20.03-LTS-SP4">acl-debugsource-2.2.53-14.oe2003sp4.x86_64.rpm</FullProductName>
			<FullProductName ProductID="libacl-2.2.53-14" CPE="cpe:/a:openEuler:openEuler:20.03-LTS-SP4">libacl-2.2.53-14.oe2003sp4.x86_64.rpm</FullProductName>
			<FullProductName ProductID="libacl-devel-2.2.53-14" CPE="cpe:/a:openEuler:openEuler:20.03-LTS-SP4">libacl-devel-2.2.53-14.oe2003sp4.x86_64.rpm</FullProductName>
			<FullProductName ProductID="acl-2.3.1-7" CPE="cpe:/a:openEuler:openEuler:22.03-LTS-SP4">acl-2.3.1-7.oe2203sp4.x86_64.rpm</FullProductName>
			<FullProductName ProductID="acl-debuginfo-2.3.1-7" CPE="cpe:/a:openEuler:openEuler:22.03-LTS-SP4">acl-debuginfo-2.3.1-7.oe2203sp4.x86_64.rpm</FullProductName>
			<FullProductName ProductID="acl-debugsource-2.3.1-7" CPE="cpe:/a:openEuler:openEuler:22.03-LTS-SP4">acl-debugsource-2.3.1-7.oe2203sp4.x86_64.rpm</FullProductName>
			<FullProductName ProductID="libacl-2.3.1-7" CPE="cpe:/a:openEuler:openEuler:22.03-LTS-SP4">libacl-2.3.1-7.oe2203sp4.x86_64.rpm</FullProductName>
			<FullProductName ProductID="libacl-devel-2.3.1-7" CPE="cpe:/a:openEuler:openEuler:22.03-LTS-SP4">libacl-devel-2.3.1-7.oe2203sp4.x86_64.rpm</FullProductName>
			<FullProductName ProductID="acl-2.3.1-7" CPE="cpe:/a:openEuler:openEuler:24.03-LTS-SP1">acl-2.3.1-7.oe2403sp1.x86_64.rpm</FullProductName>
			<FullProductName ProductID="acl-debuginfo-2.3.1-7" CPE="cpe:/a:openEuler:openEuler:24.03-LTS-SP1">acl-debuginfo-2.3.1-7.oe2403sp1.x86_64.rpm</FullProductName>
			<FullProductName ProductID="acl-debugsource-2.3.1-7" CPE="cpe:/a:openEuler:openEuler:24.03-LTS-SP1">acl-debugsource-2.3.1-7.oe2403sp1.x86_64.rpm</FullProductName>
			<FullProductName ProductID="libacl-2.3.1-7" CPE="cpe:/a:openEuler:openEuler:24.03-LTS-SP1">libacl-2.3.1-7.oe2403sp1.x86_64.rpm</FullProductName>
			<FullProductName ProductID="libacl-devel-2.3.1-7" CPE="cpe:/a:openEuler:openEuler:24.03-LTS-SP1">libacl-devel-2.3.1-7.oe2403sp1.x86_64.rpm</FullProductName>
			<FullProductName ProductID="acl-2.3.1-7" CPE="cpe:/a:openEuler:openEuler:24.03-LTS-SP3">acl-2.3.1-7.oe2403sp3.x86_64.rpm</FullProductName>
			<FullProductName ProductID="acl-debuginfo-2.3.1-7" CPE="cpe:/a:openEuler:openEuler:24.03-LTS-SP3">acl-debuginfo-2.3.1-7.oe2403sp3.x86_64.rpm</FullProductName>
			<FullProductName ProductID="acl-debugsource-2.3.1-7" CPE="cpe:/a:openEuler:openEuler:24.03-LTS-SP3">acl-debugsource-2.3.1-7.oe2403sp3.x86_64.rpm</FullProductName>
			<FullProductName ProductID="libacl-2.3.1-7" CPE="cpe:/a:openEuler:openEuler:24.03-LTS-SP3">libacl-2.3.1-7.oe2403sp3.x86_64.rpm</FullProductName>
			<FullProductName ProductID="libacl-devel-2.3.1-7" CPE="cpe:/a:openEuler:openEuler:24.03-LTS-SP3">libacl-devel-2.3.1-7.oe2403sp3.x86_64.rpm</FullProductName>
			<FullProductName ProductID="acl-2.3.1-7" CPE="cpe:/a:openEuler:openEuler:24.03-LTS-SP4">acl-2.3.1-7.oe2403sp4.x86_64.rpm</FullProductName>
			<FullProductName ProductID="acl-debuginfo-2.3.1-7" CPE="cpe:/a:openEuler:openEuler:24.03-LTS-SP4">acl-debuginfo-2.3.1-7.oe2403sp4.x86_64.rpm</FullProductName>
			<FullProductName ProductID="acl-debugsource-2.3.1-7" CPE="cpe:/a:openEuler:openEuler:24.03-LTS-SP4">acl-debugsource-2.3.1-7.oe2403sp4.x86_64.rpm</FullProductName>
			<FullProductName ProductID="libacl-2.3.1-7" CPE="cpe:/a:openEuler:openEuler:24.03-LTS-SP4">libacl-2.3.1-7.oe2403sp4.x86_64.rpm</FullProductName>
			<FullProductName ProductID="libacl-devel-2.3.1-7" CPE="cpe:/a:openEuler:openEuler:24.03-LTS-SP4">libacl-devel-2.3.1-7.oe2403sp4.x86_64.rpm</FullProductName>
		</Branch>
		<Branch Type="Package Arch" Name="noarch">
			<FullProductName ProductID="acl-help-2.2.53-14" CPE="cpe:/a:openEuler:openEuler:20.03-LTS-SP4">acl-help-2.2.53-14.oe2003sp4.noarch.rpm</FullProductName>
			<FullProductName ProductID="acl-help-2.3.1-7" CPE="cpe:/a:openEuler:openEuler:22.03-LTS-SP4">acl-help-2.3.1-7.oe2203sp4.noarch.rpm</FullProductName>
			<FullProductName ProductID="acl-help-2.3.1-7" CPE="cpe:/a:openEuler:openEuler:24.03-LTS-SP1">acl-help-2.3.1-7.oe2403sp1.noarch.rpm</FullProductName>
			<FullProductName ProductID="acl-help-2.3.1-7" CPE="cpe:/a:openEuler:openEuler:24.03-LTS-SP3">acl-help-2.3.1-7.oe2403sp3.noarch.rpm</FullProductName>
			<FullProductName ProductID="acl-help-2.3.1-7" CPE="cpe:/a:openEuler:openEuler:24.03-LTS-SP4">acl-help-2.3.1-7.oe2403sp4.noarch.rpm</FullProductName>
		</Branch>
	</ProductTree>
	<Vulnerability Ordinal="1" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
		<Notes>
			<Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">acl before version 2.4.0 contains a symlink traversal vulnerability in the libacl pathname-based functions acl_get_file(), acl_set_file(), acl_extended_file(), and acl_delete_def_file() that allows local attackers to escalate privileges by replacing any pathname component with a symbolic link. Attackers who control any component of a pathname processed by a privileged caller can redirect ACL read or write operations to arbitrary files or directories, enabling unauthorized manipulation of access control lists and local privilege escalation.</Note>
		</Notes>
		<ReleaseDate>2026-07-19</ReleaseDate>
		<CVE>CVE-2026-54369</CVE>
		<ProductStatuses>
			<Status Type="Fixed">
				<ProductID>openEuler-20.03-LTS-SP4</ProductID>
				<ProductID>openEuler-22.03-LTS-SP4</ProductID>
				<ProductID>openEuler-24.03-LTS-SP1</ProductID>
				<ProductID>openEuler-24.03-LTS-SP3</ProductID>
				<ProductID>openEuler-24.03-LTS-SP4</ProductID>
			</Status>
		</ProductStatuses>
		<Threats>
			<Threat Type="Impact">
				<Description>High</Description>
			</Threat>
		</Threats>
		<CVSSScoreSets>
			<ScoreSet>
				<BaseScore>7.1</BaseScore>
				<Vector>AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N</Vector>
			</ScoreSet>
		</CVSSScoreSets>
		<Remediations>
			<Remediation Type="Vendor Fix">
				<Description>acl security update</Description>
				<DATE>2026-07-19</DATE>
				<URL>https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-3079</URL>
			</Remediation>
		</Remediations>
	</Vulnerability>
	<Vulnerability Ordinal="2" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
		<Notes>
			<Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">acl before version 2.4.0 contains a time-of-check to time-of-use (TOCTOU) race condition vulnerability that allows local attackers to escalate privileges by replacing a pathname component with a symbolic link between an lstat() check and subsequent symlink-following operations such as stat(), chown(), chmod(), acl_get_file(), and acl_set_file(). Attackers who control a pathname component can redirect file access control list operations to arbitrary files when getfacl, setfacl, or chacl is invoked by a privileged process over an attacker-controlled path, resulting in local privilege escalation.</Note>
		</Notes>
		<ReleaseDate>2026-07-19</ReleaseDate>
		<CVE>CVE-2026-54370</CVE>
		<ProductStatuses>
			<Status Type="Fixed">
				<ProductID>openEuler-20.03-LTS-SP4</ProductID>
				<ProductID>openEuler-22.03-LTS-SP4</ProductID>
				<ProductID>openEuler-24.03-LTS-SP1</ProductID>
				<ProductID>openEuler-24.03-LTS-SP3</ProductID>
				<ProductID>openEuler-24.03-LTS-SP4</ProductID>
			</Status>
		</ProductStatuses>
		<Threats>
			<Threat Type="Impact">
				<Description>Medium</Description>
			</Threat>
		</Threats>
		<CVSSScoreSets>
			<ScoreSet>
				<BaseScore>6.3</BaseScore>
				<Vector>AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N</Vector>
			</ScoreSet>
		</CVSSScoreSets>
		<Remediations>
			<Remediation Type="Vendor Fix">
				<Description>acl security update</Description>
				<DATE>2026-07-19</DATE>
				<URL>https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-3079</URL>
			</Remediation>
		</Remediations>
	</Vulnerability>
</cvrfdoc>