Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-54229— Abrt: chownproblemdir succeeds during active post-create event processing due to inadequate locking

Quick assessment

Affected
Red Hat Red Hat Enterprise Linux 7 Extended Lifecycle Support
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

abrt project abrt是abrt project团队开源的一套自动化故障报告工具。 abrt project ABRT存在竞争条件问题漏洞,该漏洞源于abrt - dbus D - Bus 服务的 ChownProblemDir 方法,ChownProblemDir 以 DD_OPEN_READONLY 打开转储目录,并调用 dd_chown 将所有文件的所有权更改为调用者的 uid,即便 post - create 事件处理程序持有写锁时此操作也能成功,导致攻击者可在特权事件脚本仍在运行时获

CVSS 7.0 · High EPSS 0.12% · P2

Possible ATT&CK Techniques 1 AI

T1546.001 · Change Default File Association
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-54229

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Abrt: chownproblemdir succeeds during active post-create event processing due to inadequate locking
Source: CVE Program / CVE List V5
Vulnerability Description
A race condition was found in the abrt-dbus D-Bus service's ChownProblemDir method. ChownProblemDir opens the dump directory with DD_OPEN_READONLY and calls dd_chown to change ownership of all files to the caller's uid, succeeding even while post-create event handlers hold a write lock. This allows an attacker to gain filesystem-level control of the dump directory while privileged event scripts are still running.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
使用共享资源的并发执行不恰当同步问题(竞争条件)
Source: CVE Program / CVE List V5
Vulnerability Title
abrt project ABRT 竞争条件问题漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
abrt project abrt是abrt project团队开源的一套自动化故障报告工具。 abrt project ABRT存在竞争条件问题漏洞,该漏洞源于abrt - dbus D - Bus 服务的 ChownProblemDir 方法,ChownProblemDir 以 DD_OPEN_READONLY 打开转储目录,并调用 dd_chown 将所有文件的所有权更改为调用者的 uid,即便 post - create 事件处理程序持有写锁时此操作也能成功,导致攻击者可在特权事件脚本仍在运行时获
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

Vendor Product Affected Versions CPE Subscribe
Red Hat Red Hat Enterprise Linux 7 Extended Lifecycle Support 0:2.1.11-61.el7_9 ~ * cpe:/o:redhat:rhel_els:7
Red Hat Red Hat Enterprise Linux 8 0:2.10.9-26.el8_10 ~ * cpe:/a:redhat:enterprise_linux:8::appstream
Red Hat Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support 0:2.10.9-25.el8_4.1 ~ * cpe:/a:redhat:rhel_aus:8.4::appstream
Red Hat Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On 0:2.10.9-25.el8_4.1 ~ * cpe:/a:redhat:rhel_aus:8.4::appstream
Red Hat Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support 0:2.10.9-25.el8_6.1 ~ * cpe:/a:redhat:rhel_aus:8.6::appstream
Red Hat Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On 0:2.10.9-25.el8_6.1 ~ * cpe:/a:redhat:rhel_aus:8.6::appstream
Red Hat Red Hat Enterprise Linux 8.8 Telecommunications Update Service 0:2.10.9-25.el8_8.1 ~ * cpe:/a:redhat:rhel_e4s:8.8::appstream
Red Hat Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions 0:2.10.9-25.el8_8.1 ~ * cpe:/a:redhat:rhel_e4s:8.8::appstream
Red Hat Red Hat Enterprise Linux 6 - cpe:/o:redhat:enterprise_linux:6

II. Public POCs for CVE-2026-54229

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-54229

请登录查看更多情报信息。

Vendor Advisories for CVE-2026-54229 (7)

Same Patch Batch · Red Hat · 2026-06-13 · 4 CVEs total

CVE-2026-54228 7.8 HIGH Abrt: toctou race condition in abrt-dbus setelement allows arbitrary file writes to dump d
CVE-2026-54230 7.0 HIGH Abrt: event handler scripts follow symlinks when writing output files, allowing arbitrary
CVE-2026-54231 5.5 MEDIUM Abrt: unsanitized systemd journal content written to dump directory files enables content

IV. Related Vulnerabilities

V. Comments for CVE-2026-54229

No comments yet


Leave a comment