A race condition was found in the abrt-dbus D-Bus service's ChownProblemDir method. ChownProblemDir opens the dump directory with DD_OPEN_READONLY and calls dd_chown to change ownership of all files to the caller's uid, succeeding even while post-create event handlers hold a write lock. This allows an attacker to gain filesystem-level control of the dump directory while privileged event scripts are still running.
CVSS Details
- CVSS 3.1 Base Score: 7
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Redhat_linux | — | Upgrade abrt-develUpgrade abrt-addon-kerneloopsUpgrade abrt-addon-coredump-helper-debuginfoUpgrade abrt-cli-ngUpgrade abrt-atomic-debuginfoUpgrade abrt-retrace-client-debuginfoNo solution existsUpgrade abrt-gui-debuginfoUpgrade abrt-debuginfoUpgrade abrt-pythonUpgrade abrt-addon-ccppUpgrade python3-abrt-addonUpgrade abrt-addon-pythonUpgrade abrt-addon-xorgUpgrade abrt-addon-pstoreoopsUpgrade abrt-gui-libsUpgrade abrt-addon-xorg-debuginfoUpgrade abrt-addon-upload-watch-debuginfoUpgrade abrt-addon-ccpp-debuginfoUpgrade abrt-libsUpgrade abrt-gui-develUpgrade abrt-desktopUpgrade abrt-libs-debuginfoUpgrade abrt-python-docUpgrade abrt-console-notificationUpgrade python3-abrt-debuginfoUpgrade abrt-addon-upload-watchUpgrade abrt-plugin-sosreportUpgrade abrt-dbusUpgrade python3-abrtUpgrade abrt-gui-libs-debuginfoUpgrade abrt-dbus-debuginfoUpgrade abrt-debugsourceUpgrade abrtUpgrade abrt-retrace-clientUpgrade abrt-guiUpgrade abrt-addon-kerneloops-debuginfoUpgrade abrt-tuiUpgrade python3-abrt-docUpgrade python3-abrt-container-addonUpgrade abrt-plugin-machine-idUpgrade abrt-tui-debuginfoUpgrade abrt-cliUpgrade abrt-addon-pstoreoops-debuginfoUpgrade abrt-addon-vmcoreUpgrade abrt-addon-coredump-helper | Jul 17, 2026 | May 4, 2026 |
| Rocky_linux | — | Upgrade abrt-cliUpgrade abrt-cli-ngUpgrade abrt-gui-debuginfoUpgrade abrt-addon-xorgUpgrade abrt-dbus-debuginfoUpgrade abrt-addon-pstoreoops-debuginfoUpgrade python3-abrt-addonUpgrade abrt-addon-ccppUpgrade abrt-addon-pstoreoopsUpgrade abrt-plugin-sosreportUpgrade abrt-libsUpgrade abrtUpgrade abrt-tuiUpgrade abrt-gui-libs-debuginfoUpgrade abrt-addon-kerneloops-debuginfoUpgrade abrt-desktopUpgrade abrt-addon-ccpp-debuginfoUpgrade abrt-tui-debuginfoUpgrade abrt-gui-libsUpgrade abrt-dbusUpgrade python3-abrt-debuginfoUpgrade abrt-debugsourceUpgrade python3-abrtUpgrade python3-abrt-container-addonUpgrade abrt-addon-coredump-helperUpgrade abrt-libs-debuginfoUpgrade abrt-debuginfoUpgrade abrt-addon-vmcoreUpgrade abrt-addon-kerneloopsUpgrade abrt-plugin-machine-idUpgrade abrt-guiUpgrade abrt-console-notificationUpgrade abrt-addon-xorg-debuginfoUpgrade abrt-addon-coredump-helper-debuginfo | Aug 14, 2026 | Aug 13, 2026 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub