[CLSA-2026:1787146803] attr: Fix of CVE-2026-54371
Type:
security
Severity:
Moderate
Release date:
2026-08-19 13:40:14 UTC
Description:
- Rebase to attr-2.6.0; CVE-2026-54371 fixed upstream - setfattr: new -P/--physical option; --restore is symlink-safe only with -P - setfattr --restore now warns on stderr when -P/-h are absent - getfattr -Rh now recurses through a symlink argument (previously no output)
CVEs fixed:
Updated packages:
  • attr-2.6.0-1.el9_2.tuxcare.els1.x86_64.rpm
    sha:749266fcbeea5a697b0a76f76f26895dc4de2147672f43c4e05b4e9d57b0cf37
  • libattr-2.6.0-1.el9_2.tuxcare.els1.i686.rpm
    sha:0811705341893ffcd4f12a4c2f90d333f0fd21b34282c07682c7b809d71e840e
  • libattr-2.6.0-1.el9_2.tuxcare.els1.x86_64.rpm
    sha:1042129884777414f1bc46727aba9b02d2a944517727460afa9350f42e5d8eb9
  • libattr-devel-2.6.0-1.el9_2.tuxcare.els1.i686.rpm
    sha:784df14749a5e53390d8231738e10a2d1bf1adcce8ad2f87d3a1eef9efd2a376
  • libattr-devel-2.6.0-1.el9_2.tuxcare.els1.x86_64.rpm
    sha:a6c56b52fbbd8f0616dddaad67fb8c6bb50c639eeeab07c9b46ce2b0b012710d
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.