Issued at: 2026-08-13
Updated at: 2026-08-13
Advisory content derived from Red Hat RHSA-2026:54272, © Red Hat, Inc., used under CC BY 4.0, with modifications.
Synopsis
Important: abrt security update
Description
The Automatic Bug Reporting Tool (ABRT) recognizes defects in applications and creates bug reports that help maintainers fix the defects. ABRT uses a plug-in system to extend its functionality.
Security Fix(es):
* abrt: TOCTOU race condition in abrt-dbus SetElement allows arbitrary file writes to dump directories (CVE-2026-54228)
* abrt: ChownProblemDir succeeds during active post-create event processing due to inadequate locking (CVE-2026-54229)
* abrt: event handler scripts follow symlinks when writing output files, allowing arbitrary file overwrites (CVE-2026-54230)
* abrt: unsanitized systemd journal content written to dump directory files enables content injection (CVE-2026-54231)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.