A race condition was found in the abrt-dbus D-Bus service's ChownProblemDir method. ChownProblemDir opens the dump directory with DD_OPEN_READONLY and calls dd_chown to change ownership of all files to the caller's uid, succeeding even while post-create event handlers hold a write lock. This allows an attacker to gain filesystem-level control of the dump directory while privileged event scripts are still running.
CVSS Details
- CVSS 3.1 Base Score: 7
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Redhat_linux | — | No solution existsUpgrade abrt-pythonUpgrade abrt-addon-kerneloopsUpgrade abrt-desktopUpgrade abrt-addon-pythonUpgrade abrt-develUpgrade abrt-addon-pstoreoopsUpgrade abrt-python-docUpgrade abrt-gui-develUpgrade abrt-debuginfoUpgrade abrt-addon-ccppUpgrade abrt-libsUpgrade abrt-addon-xorgUpgrade abrt-gui-libsUpgrade abrtUpgrade abrt-cliUpgrade abrt-retrace-clientUpgrade abrt-guiUpgrade abrt-dbusUpgrade abrt-addon-upload-watchUpgrade abrt-addon-vmcoreUpgrade abrt-console-notificationUpgrade abrt-tui | Jul 17, 2026 | May 4, 2026 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub