Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1325 CNY

100%

CVE-2026-54230— Abrt: event handler scripts follow symlinks when writing output files, allowing arbitrary file overwrites

CVSS 7.0 · High EPSS 0.12% · P2

Possible ATT&CK Techniques 1AI

T1548.002 · Bypass User Account Control

Affected Version Matrix 3

Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2026-54230

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Abrt: event handler scripts follow symlinks when writing output files, allowing arbitrary file overwrites
Source: NVD (National Vulnerability Database)
Vulnerability Description
A symlink following vulnerability was found in the ABRT post-create event handler scripts in libreport. Event scripts write output files using shell redirections without the O_NOFOLLOW flag. If the target file is replaced with a symlink, the shell process running as root follows the symlink and writes content to the symlink target, allowing arbitrary file overwrites on the system.
Source: NVD (National Vulnerability Database)
CVSS Information
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Source: NVD (National Vulnerability Database)
Vulnerability Type
在文件访问前对链接解析不恰当(链接跟随)
Source: NVD (National Vulnerability Database)
Vulnerability Title
Redhat libreport 后置链接漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Redhat libreport是美国Redhat公司开源的一个问题报告通用库。 Redhat libreport存在后置链接漏洞,该漏洞源于事件脚本使用 shell 重定向写入输出文件时未设置 O_NOFOLLOW 标志,若目标文件被替换为符号链接,以 root 身份运行的 shell 进程会跟随该符号链接并将内容写入符号链接指向的目标,导致系统上可发生任意文件覆盖。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
Red HatRed Hat Enterprise Linux 6-cpe:/o:redhat:enterprise_linux:6
Red HatRed Hat Enterprise Linux 7-cpe:/o:redhat:enterprise_linux:7
Red HatRed Hat Enterprise Linux 8-cpe:/o:redhat:enterprise_linux:8

II. Public POCs for CVE-2026-54230

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-54230

登录查看更多情报信息。

Vendor Advisories for CVE-2026-54230 (2)

Same Patch Batch · Red Hat · 2026-06-13 · 4 CVEs total

CVE-2026-542287.8 HIGHAbrt: toctou race condition in abrt-dbus setelement allows arbitrary file writes to dump d
CVE-2026-542297.0 HIGHAbrt: chownproblemdir succeeds during active post-create event processing due to inadequat
CVE-2026-542315.5 MEDIUMAbrt: unsanitized systemd journal content written to dump directory files enables content

IV. Related Vulnerabilities

V. Comments for CVE-2026-54230

No comments yet


Leave a comment