|
|
Log in / Subscribe / Register

Ubuntu alert USN-8691-1 (attr)

From:  noreply+usn-bot--- via ubuntu-security-announce <ubuntu-security-announce@lists.ubuntu.com>
To:  ubuntu-security-announce@lists.ubuntu.com
Subject:  [USN-8691-1] attr vulnerability
Date:  Mon, 31 Aug 2026 15:41:54 +0000
Message-ID:  <E1x148w-0006ah-Kf@lists.ubuntu.com>
Cc:  noreply+usn-bot@canonical.com

========================================================================== Ubuntu Security Notice USN-8691-1 August 31, 2026 attr vulnerability ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 26.04 LTS - Ubuntu 24.04 LTS - Ubuntu 22.04 LTS - Ubuntu 20.04 LTS - Ubuntu 18.04 LTS - Ubuntu 16.04 LTS - Ubuntu 14.04 LTS Summary: attr could allow a local attacker to gain elevated privileges. Software Description: - attr: utilities for manipulating file system extended attributes Details: It was discovered that attr incorrectly handled symbolic links while traversing directory paths. A local attacker who controlled a pathname component could possibly use this issue to redirect privileged attr operations to arbitrary files and gain elevated privileges. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 26.04 LTS attr 1:2.5.2-4ubuntu0.1 libattr1 1:2.5.2-4ubuntu0.1 Ubuntu 24.04 LTS attr 1:2.5.2-1ubuntu0.1 libattr1 1:2.5.2-1ubuntu0.1 Ubuntu 22.04 LTS attr 1:2.5.1-1ubuntu0.1 libattr1 1:2.5.1-1ubuntu0.1 Ubuntu 20.04 LTS attr 1:2.4.48-5ubuntu0.1~esm1 Available with Ubuntu Pro libattr1 1:2.4.48-5ubuntu0.1~esm1 Available with Ubuntu Pro Ubuntu 18.04 LTS attr 1:2.4.47-2ubuntu0.18.04.1~esm1 Available with Ubuntu Pro libattr1 1:2.4.47-2ubuntu0.18.04.1~esm1 Available with Ubuntu Pro Ubuntu 16.04 LTS attr 1:2.4.47-2ubuntu0.16.04.1~esm1 Available with Ubuntu Pro libattr1 1:2.4.47-2ubuntu0.16.04.1~esm1 Available with Ubuntu Pro Ubuntu 14.04 LTS attr 1:2.4.47-1ubuntu1+esm1 Available with Ubuntu Pro libattr1 1:2.4.47-1ubuntu1+esm1 Available with Ubuntu Pro In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-8691-1 CVE-2026-54371 Package Information: https://launchpad.net/ubuntu/+source/attr/1:2.5.2-4ubuntu0.1 https://launchpad.net/ubuntu/+source/attr/1:2.5.2-1ubuntu0.1 https://launchpad.net/ubuntu/+source/attr/1:2.5.1-1ubuntu0.1


Attachment: signature.asc (type=application/pgp-signature)

-----BEGIN PGP SIGNATURE----- iQIzBAABCgAdFiEE+8neBLO2Hp/ppPlOcpJm3tlzhgEFAmqVoIoACgkQcpJm3tlz hgFHwQ/8D+5p/mxHAceCKLQ8rErDE2H0/lqPl1bfoeWzLa65iaUbI5UEzokeGyHj ot42HwjldTjSbmAq49tg5nlrwOIPpm31aJHOAe5LG6QUrFU38qJPNFaTQLHMQC2X 93f7Nvx0UKxR2wGOppZq/tFfRXV/F9rYip+PcLU+j0LwWpZoWY6hkCnRqX6vy4HU Iq0uYLVoUV2joIYBhgctq+3Gzxa0vEfQFJZbELATPSH2dvxIyrqunMWBZccQNp6i 3/9NAomve78DNkfoGEFCnhMzxQcukYh6FUs/u+WoL3YPV471xspij87/gxraICYI CR2n1JRrfjYTDD7qUGGuzfhslizAwnXish8OXaaH4WnL/prqvGl6S8hrjNVLsw9T BiMWLpYrFj1QPg7LfMyUXn1JGrCyP4i+oZi2kLwiVLw9f4YOO0D0qpys09dgY4wu 8TI9ljRgO5i09HzxUPxD/zTnkTJEpSkNjWBP66h4HohVVSwfZNKpw7UL1qMxbjzK WvfGJ90NWNbg6urR3b5koCVB2quDWo0iVSyMTmryua13ZrY8V3GO6qAjRNJ2L7HT mfGFskhvDOurGcR7uR06KqafOMwON0MzazjDnKIm2uyX+ERXYu0AzwvsrkDoV4km D4cWSnMGfzGwBEpSBUbcwjn8xb5JcD0fbRFPEDII81SjL3k1xY4= =M1FQ -----END PGP SIGNATURE-----


to post comments


Copyright © 2026, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds