CVE-2026-54230
published 2026-06-13CVE-2026-54230: A symlink following vulnerability was found in the ABRT post-create event handler scripts in libreport. Event scripts write output files using shell…
PriorityP345high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.14%
3.7th percentile
A symlink following vulnerability was found in the ABRT post-create event handler scripts in libreport. Event scripts write output files using shell redirections without the O_NOFOLLOW flag. If the target file is replaced with a symlink, the shell process running as root follows the symlink and writes content to the symlink target, allowing arbitrary file overwrites on the system.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| abrt | abrt | — | — |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux | — | — |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
vendor_redhat7.0HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Red Hat Enterprise Linux 6/7/8 link following (EUVD-2026-36639)
vuldb·2026-06-13·CVSS 7.0
CVE-2026-54230 [HIGH] Red Hat Enterprise Linux 6/7/8 link following (EUVD-2026-36639)
A vulnerability was found in Red Hat Enterprise Linux 6/7/8. It has been classified as critical. This impacts an unknown function. This manipulation causes link following.
This vulnerability appears as CVE-2026-54230. The attack requires local access. There is no available exploit.
GHSA
A symlink following vulnerability was found in the ABRT post-create event handler scripts in libreport.
ghsa_unreviewed·2026-06-13
CVE-2026-54230 [HIGH] CWE-59 A symlink following vulnerability was found in the ABRT post-create event handler scripts in libreport.
A symlink following vulnerability was found in the ABRT post-create event handler scripts in libreport. Event scripts write output files using shell redirections without the O_NOFOLLOW flag. If the target file is replaced with a symlink, the shell process running as root follows the symlink and writes content to the symlink target, allowing arbitrary file overwrites on the system.
Red Hat
abrt: event handler scripts follow symlinks when writing output files, allowing arbitrary file overwrites
vendor_redhat·2026-05-04·CVSS 7.0
CVE-2026-54230 [HIGH] CWE-59 abrt: event handler scripts follow symlinks when writing output files, allowing arbitrary file overwrites
abrt: event handler scripts follow symlinks when writing output files, allowing arbitrary file overwrites
A symlink following vulnerability was found in the ABRT post-create event handler scripts in libreport. Event scripts write output files using shell redirections without the O_NOFOLLOW flag. If the target file is replaced with a symlink, the shell process running as root follows the symlink and writes content to the symlink target, allowing arbitrary file overwrites on the system.
Statement: Red Hat is aware of this vulnerability affecting ABRT event handler scripts in libreport. ABRT was deprecated in Red Hat Enterprise Linux 8 and is not available in Red Hat Enterprise Linux 9 or later. Users of RHEL 8 who have ABRT installed are encouraged to disable or remove it. Fedora users are
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2026-54230 abrt: event handler scripts follow symlinks when writing output files, allowing arbitrary file overwrites
bugzilla·2026-06-12
CVE-2026-54230 [HIGH] CVE-2026-54230 abrt: event handler scripts follow symlinks when writing output files, allowing arbitrary file overwrites
CVE-2026-54230 abrt: event handler scripts follow symlinks when writing output files, allowing arbitrary file overwrites
A symlink following vulnerability was found in the ABRT post-create event handler scripts in /etc/libreport/events.d/abrt_event.conf. Event scripts write output files using shell redirections (e.g., "printf ... > $DUMP_DIR/var_log_messages") which use open() with O_WRONLY|O_CREAT|O_TRUNC without the O_NOFOLLOW flag. If the target file is replaced with a symlink, the shell process (running as root in the abrt_handle_event_t SELinux domain, which is effectively unconfined) follows the symlink and writes content to the symlink target. In contrast, dd_save_text (used by SetElement) correctly uses O_NOFOLLOW. An attacker who has gained filesystem control of the dump director
Bugzilla
CVE-2026-54230 abrt: event handler scripts follow symlinks when writing output files, allowing arbitrary file overwrites [fedora-all]
bugzilla·2026-06-12
CVE-2026-54230 [HIGH] CVE-2026-54230 abrt: event handler scripts follow symlinks when writing output files, allowing arbitrary file overwrites [fedora-all]
CVE-2026-54230 abrt: event handler scripts follow symlinks when writing output files, allowing arbitrary file overwrites [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
2026-06-13
Published