[CLSA-2026:1787148007] attr: Fix of CVE-2026-54371
Type:
security
Severity:
Moderate
Release date:
2026-08-19 14:00:17 UTC
Description:
- Rebase to attr-2.6.0; CVE-2026-54371 fixed upstream - setfattr: new -P/--physical option; --restore is symlink-safe only with -P - setfattr --restore now warns on stderr when -P/-h are absent - getfattr -Rh now recurses through a symlink argument (previously no output)
CVEs fixed:
Updated packages:
  • attr-2.6.0-1.el9_6.tuxcare.els1.x86_64.rpm
    sha:10c9ab4e3731faea6f8a40e63289e04ff57a77f0dcf66d329a98f83fe73af9ed
  • libattr-2.6.0-1.el9_6.tuxcare.els1.i686.rpm
    sha:113366dd68f01dbf864ac97a5ee16b270d0a0e9038d11c5f2531368db72f9bbb
  • libattr-2.6.0-1.el9_6.tuxcare.els1.x86_64.rpm
    sha:204cd31a798bfada9c056f04b7bfc73a08a58159693c0eaae2164b3ef064ffe5
  • libattr-devel-2.6.0-1.el9_6.tuxcare.els1.i686.rpm
    sha:74eb46c0ad5f39aa2733ae78447c144583e514dfe04282ce0f095b1121cc33dd
  • libattr-devel-2.6.0-1.el9_6.tuxcare.els1.x86_64.rpm
    sha:a19a08a3a7abe5d1621f8fc63326f01f3c4e36f1b31cba8e1d6e0ddae64cff2c
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.