abrt project abrt是abrt project团队开源的一套自动化故障报告工具。 abrt project ABRT存在竞争条件问题漏洞,该漏洞源于abrt - dbus D - Bus 服务的 ChownProblemDir 方法,ChownProblemDir 以 DD_OPEN_READONLY 打开转储目录,并调用 dd_chown 将所有文件的所有权更改为调用者的 uid,即便 post - create 事件处理程序持有写锁时此操作也能成功,导致攻击者可在特权事件脚本仍在运行时获
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Red Hat | Red Hat Enterprise Linux 6 | any |
unknown |
| Red Hat | Red Hat Enterprise Linux 7 Extended Lifecycle Support | 0:2.1.11-61.el7_9< * |
unaffected |
| Red Hat | Red Hat Enterprise Linux 8 | 0:2.10.9-26.el8_10< * |
unaffected |
| Red Hat | Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support | 0:2.10.9-25.el8_4.1< * |
unaffected |
| Red Hat | Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On | 0:2.10.9-25.el8_4.1< * |
unaffected |
| Red Hat | Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support | 0:2.10.9-25.el8_6.1< * |
unaffected |
| Red Hat | Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On | 0:2.10.9-25.el8_6.1< * |
unaffected |
| Red Hat | Red Hat Enterprise Linux 8.8 Telecommunications Update Service | 0:2.10.9-25.el8_8.1< * |
unaffected |
| Red Hat | Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions | 0:2.10.9-25.el8_8.1< * |
unaffected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Red Hat | Red Hat Enterprise Linux 7 Extended Lifecycle Support | 0:2.1.11-61.el7_9 ~ * |
cpe:/o:redhat:rhel_els:7
|
|
| Red Hat | Red Hat Enterprise Linux 8 | 0:2.10.9-26.el8_10 ~ * |
cpe:/a:redhat:enterprise_linux:8::appstream
|
|
| Red Hat | Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support | 0:2.10.9-25.el8_4.1 ~ * |
cpe:/a:redhat:rhel_aus:8.4::appstream
|
|
| Red Hat | Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On | 0:2.10.9-25.el8_4.1 ~ * |
cpe:/a:redhat:rhel_aus:8.4::appstream
|
|
| Red Hat | Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support | 0:2.10.9-25.el8_6.1 ~ * |
cpe:/a:redhat:rhel_aus:8.6::appstream
|
|
| Red Hat | Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On | 0:2.10.9-25.el8_6.1 ~ * |
cpe:/a:redhat:rhel_aus:8.6::appstream
|
|
| Red Hat | Red Hat Enterprise Linux 8.8 Telecommunications Update Service | 0:2.10.9-25.el8_8.1 ~ * |
cpe:/a:redhat:rhel_e4s:8.8::appstream
|
|
| Red Hat | Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions | 0:2.10.9-25.el8_8.1 ~ * |
cpe:/a:redhat:rhel_e4s:8.8::appstream
|
|
| Red Hat | Red Hat Enterprise Linux 6 | - |
cpe:/o:redhat:enterprise_linux:6
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-54228 | 7.8 HIGH | Abrt: toctou race condition in abrt-dbus setelement allows arbitrary file writes to dump d |
| CVE-2026-54230 | 7.0 HIGH | Abrt: event handler scripts follow symlinks when writing output files, allowing arbitrary |
| CVE-2026-54231 | 5.5 MEDIUM | Abrt: unsanitized systemd journal content written to dump directory files enables content |
No comments yet