Redhat libreport是美国Redhat公司开源的一个问题报告通用库。 Redhat libreport存在后置链接漏洞,该漏洞源于事件脚本使用 shell 重定向写入输出文件时未设置 O_NOFOLLOW 标志,若目标文件被替换为符号链接,以 root 身份运行的 shell 进程会跟随该符号链接并将内容写入符号链接指向的目标,导致系统上可发生任意文件覆盖。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Red Hat | Red Hat Enterprise Linux 6 | any |
unknown |
| Red Hat | Red Hat Enterprise Linux 7 | any |
affected |
| Red Hat | Red Hat Enterprise Linux 8 | 0:2.10.9-26.el8_10< * |
unaffected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Red Hat | Red Hat Enterprise Linux 8 | 0:2.10.9-26.el8_10 ~ * |
cpe:/a:redhat:enterprise_linux:8::appstream
|
|
| Red Hat | Red Hat Enterprise Linux 6 | - |
cpe:/o:redhat:enterprise_linux:6
|
|
| Red Hat | Red Hat Enterprise Linux 7 | - |
cpe:/o:redhat:enterprise_linux:7
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-54228 | 7.8 HIGH | Abrt: toctou race condition in abrt-dbus setelement allows arbitrary file writes to dump d |
| CVE-2026-54229 | 7.0 HIGH | Abrt: chownproblemdir succeeds during active post-create event processing due to inadequat |
| CVE-2026-54231 | 5.5 MEDIUM | Abrt: unsanitized systemd journal content written to dump directory files enables content |
No comments yet