PatchSiren

attr CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH attr CVE published 2026-06-29

CVE-2026-54371

The CVE-2026-54371 vulnerability affects the attr package before version 2.6.0, specifically in the getfattr and setfattr utilities, allowing local attackers to escalate privileges via symlink traversal. This HIGH-severity vulnerability has a CVSS score of 8.4. System administrators and users of the attr package, especially those using versions before 2.6.0, should verify and apply patches to prevent loca [truncated]