Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-54230— Abrt: event handler scripts follow symlinks when writing output files, allowing arbitrary file overwrites

Quick assessment

Affected
Red Hat Red Hat Enterprise Linux 8
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Redhat libreport是美国Redhat公司开源的一个问题报告通用库。 Redhat libreport存在后置链接漏洞,该漏洞源于事件脚本使用 shell 重定向写入输出文件时未设置 O_NOFOLLOW 标志,若目标文件被替换为符号链接,以 root 身份运行的 shell 进程会跟随该符号链接并将内容写入符号链接指向的目标,导致系统上可发生任意文件覆盖。

CVSS 7.0 · High EPSS 0.14% · P4

Possible ATT&CK Techniques 1 AI

T1548.002 · Bypass User Account Control

Affected Version Matrix 3

VendorProduct Version RangeStatus
Red Hat Red Hat Enterprise Linux 6 any unknown
Red Hat Red Hat Enterprise Linux 7 any affected
Red Hat Red Hat Enterprise Linux 8 0:2.10.9-26.el8_10< * unaffected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-54230

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Abrt: event handler scripts follow symlinks when writing output files, allowing arbitrary file overwrites
Source: CVE Program / CVE List V5
Vulnerability Description
A symlink following vulnerability was found in the ABRT post-create event handler scripts in libreport. Event scripts write output files using shell redirections without the O_NOFOLLOW flag. If the target file is replaced with a symlink, the shell process running as root follows the symlink and writes content to the symlink target, allowing arbitrary file overwrites on the system.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
在文件访问前对链接解析不恰当(链接跟随)
Source: CVE Program / CVE List V5
Vulnerability Title
Redhat libreport 后置链接漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Redhat libreport是美国Redhat公司开源的一个问题报告通用库。 Redhat libreport存在后置链接漏洞,该漏洞源于事件脚本使用 shell 重定向写入输出文件时未设置 O_NOFOLLOW 标志,若目标文件被替换为符号链接,以 root 身份运行的 shell 进程会跟随该符号链接并将内容写入符号链接指向的目标,导致系统上可发生任意文件覆盖。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

Vendor Product Affected Versions CPE Subscribe
Red Hat Red Hat Enterprise Linux 8 0:2.10.9-26.el8_10 ~ * cpe:/a:redhat:enterprise_linux:8::appstream
Red Hat Red Hat Enterprise Linux 6 - cpe:/o:redhat:enterprise_linux:6
Red Hat Red Hat Enterprise Linux 7 - cpe:/o:redhat:enterprise_linux:7

II. Public POCs for CVE-2026-54230

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-54230

登录查看更多情报信息。

Vendor Advisories for CVE-2026-54230 (3)

Same Patch Batch · Red Hat · 2026-06-13 · 4 CVEs total

CVE-2026-54228 7.8 HIGH Abrt: toctou race condition in abrt-dbus setelement allows arbitrary file writes to dump d
CVE-2026-54229 7.0 HIGH Abrt: chownproblemdir succeeds during active post-create event processing due to inadequat
CVE-2026-54231 5.5 MEDIUM Abrt: unsanitized systemd journal content written to dump directory files enables content

IV. Related Vulnerabilities

V. Comments for CVE-2026-54230

No comments yet


Leave a comment