Abrt: event handler scripts follow symlinks when writing output files, allowing arbitrary file overwrites
21Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 7epss 0.2%
exploitation probability
0.2%top 94% of all CVEs
observed exploitation
nono source reports it
A symlink following vulnerability was found in the ABRT post-create event handler scripts in libreport. Event scripts write output files using shell redirections without the O_NOFOLLOW flag. If the target file is replaced with a symlink, the shell process running as root follows the symlink and writes content to the symlink target, allowing arbitrary file overwrites on the system.
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Affected products
Red Hat · Red Hat Enterprise Linux 6Red Hat · Red Hat Enterprise Linux 7 Extended Lifecycle SupportRed Hat · Red Hat Enterprise Linux 8Red Hat · Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update SupportRed Hat · Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-OnRed Hat · Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update SupportRed Hat · Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-OnRed Hat · Red Hat Enterprise Linux 8.8 Telecommunications Update ServiceRed Hat · Red Hat Enterprise Linux 8.8 Update Services for SAP SolutionsReferences
https://access.redhat.com/errata/RHSA-2026:54272https://access.redhat.com/errata/RHSA-2026:69115https://access.redhat.com/errata/RHSA-2026:69116https://access.redhat.com/errata/RHSA-2026:69117https://access.redhat.com/errata/RHSA-2026:69121https://access.redhat.com/security/cve/CVE-2026-54230https://bugzilla.redhat.com/show_bug.cgi?id=2488568https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-54230.json