CVE-2026-54230 Details
Description
A symlink following vulnerability was found in the ABRT post-create event handler scripts in libreport. Event scripts write output files using shell redirections without the O_NOFOLLOW flag. If the target file is replaced with a symlink, the shell process running as root follows the symlink and writes content to the symlink target, allowing arbitrary file overwrites on the system.
A symlink following vulnerability exists in the ABRT post-create event handler scripts within libreport. The event scripts write output files using shell redirections without the O_NOFOLLOW flag. This oversight allows the shell process, running as root, to follow symlinks and overwrite arbitrary files on the system. The vulnerability affects ABRT in Red Hat Enterprise Linux 8, as well as Fedora 43 and 44.
Users on Red Hat Enterprise Linux 8 with ABRT installed are advised to disable or remove the application. Fedora users should consider using systemd-coredump for crash handling instead of ABRT.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jun 15, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-59 | Improper Link Resolution Before File Access ('Link Following') | redhat-SADP |
| CWE-59 | Improper Link Resolution Before File Access ('Link Following') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| redhat automatic bug reporting tool | All versions |
CPE
Remediation
| |
| fedoraproject fedora | 43 44 |
CPE
Remediation
| |
| redhat enterprise linux | 7.0 8.0 |
CPE
Remediation
| |
Change History
14 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 21, 2026 | CVE Modified | [email protected] |
| Sep 21, 2026 | CVE Modified | redhat-SADP |
| Sep 21, 2026 | CVE Modified | [email protected] |
| Aug 26, 2026 | CPE Deprecation Remap | [email protected] |
| Aug 13, 2026 | CVE Modified | redhat-SADP |
| Aug 12, 2026 | CVE Modified | [email protected] |
| Jul 23, 2026 | CVE Translated | [email protected] |
| Jul 15, 2026 | CVE Modified | redhat-SADP |
| Jun 30, 2026 | CVE Modified | redhat-SADP |
| Jun 29, 2026 | Reanalysis | [email protected] |
| Jun 29, 2026 | Initial Analysis | [email protected] |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jun 13, 2026 | New CVE Received | [email protected] |