A symlink following vulnerability was found in the ABRT post-create event handler scripts in libreport. Event scripts write output files using shell redirections without the O_NOFOLLOW flag. If the target file is replaced with a symlink, the shell process running as root follows the symlink and writes content to the symlink target, allowing arbitrary file overwrites on the system.
CVSS Details
- CVSS 3.1 Base Score: 7.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Redhat_linux | — | Upgrade abrt-dbus-debuginfoUpgrade abrt-tuiUpgrade abrt-addon-ccpp-debuginfoUpgrade abrt-addon-kerneloops-debuginfoUpgrade abrt-pythonNo solution existsUpgrade abrt-addon-pstoreoops-debuginfoUpgrade abrt-python-docUpgrade abrt-gui-libsUpgrade abrt-plugin-sosreportUpgrade abrtUpgrade abrt-desktopUpgrade python3-abrt-addonUpgrade abrt-addon-pstoreoopsUpgrade python3-abrt-debuginfoUpgrade python3-abrt-container-addonUpgrade abrt-cli-ngUpgrade abrt-addon-xorgUpgrade abrt-addon-ccppUpgrade abrt-cliUpgrade abrt-libsUpgrade abrt-gui-debuginfoUpgrade abrt-dbusUpgrade abrt-gui-develUpgrade abrt-gui-libs-debuginfoUpgrade abrt-addon-coredump-helper-debuginfoUpgrade abrt-addon-vmcoreUpgrade abrt-debuginfoUpgrade abrt-addon-xorg-debuginfoUpgrade abrt-console-notificationUpgrade abrt-libs-debuginfoUpgrade abrt-addon-upload-watchUpgrade abrt-plugin-machine-idUpgrade abrt-retrace-client-debuginfoUpgrade abrt-addon-pythonUpgrade abrt-develUpgrade abrt-atomic-debuginfoUpgrade python3-abrtUpgrade abrt-debugsourceUpgrade abrt-addon-kerneloopsUpgrade abrt-addon-upload-watch-debuginfoUpgrade abrt-guiUpgrade python3-abrt-docUpgrade abrt-tui-debuginfoUpgrade abrt-retrace-clientUpgrade abrt-addon-coredump-helper | Jul 17, 2026 | May 4, 2026 |
| Rocky_linux | — | Upgrade abrt-addon-pstoreoopsUpgrade abrt-addon-xorg-debuginfoUpgrade abrt-cli-ngUpgrade abrt-tui-debuginfoUpgrade python3-abrt-addonUpgrade abrt-gui-debuginfoUpgrade python3-abrt-container-addonUpgrade abrt-addon-coredump-helper-debuginfoUpgrade abrt-libsUpgrade abrt-addon-ccpp-debuginfoUpgrade abrt-desktopUpgrade abrt-addon-kerneloopsUpgrade abrt-debuginfoUpgrade abrt-addon-ccppUpgrade abrt-plugin-sosreportUpgrade abrt-addon-vmcoreUpgrade abrt-debugsourceUpgrade abrt-dbus-debuginfoUpgrade abrt-cliUpgrade abrtUpgrade abrt-gui-libsUpgrade python3-abrt-debuginfoUpgrade abrt-libs-debuginfoUpgrade abrt-addon-xorgUpgrade abrt-gui-libs-debuginfoUpgrade abrt-guiUpgrade abrt-dbusUpgrade abrt-addon-pstoreoops-debuginfoUpgrade abrt-tuiUpgrade abrt-plugin-machine-idUpgrade abrt-addon-kerneloops-debuginfoUpgrade python3-abrtUpgrade abrt-addon-coredump-helperUpgrade abrt-console-notification | Aug 14, 2026 | Aug 13, 2026 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub