← voltar
CVE-2026-54230highCWE-59

Abrt: event handler scripts follow symlinks when writing output files, allowing arbitrary file overwrites

21Vexday Risk Score

Sem sinal de exploração. Nenhum artefato público de exploração conhecido até agora.

ssvc Trackcvss 7epss 0.1%
probabilidade de exploração
0.1%top 96% das CVEs
exploração observada
nãonenhuma fonte reporta
A symlink following vulnerability was found in the ABRT post-create event handler scripts in libreport. Event scripts write output files using shell redirections without the O_NOFOLLOW flag. If the target file is replaced with a symlink, the shell process running as root follows the symlink and writes content to the symlink target, allowing arbitrary file overwrites on the system.
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H