abrt-2.10.9-26.el8_10.ML.1
エラータID: AXSA:2026-1725:01
The Automatic Bug Reporting Tool (ABRT) recognizes defects in applications and creates bug reports that help maintainers fix the defects. ABRT uses a plug-in system to extend its functionality.
Security Fix(es):
* abrt: TOCTOU race condition in abrt-dbus SetElement allows arbitrary file writes to dump directories (CVE-2026-54228)
* abrt: ChownProblemDir succeeds during active post-create event processing due to inadequate locking (CVE-2026-54229)
* abrt: event handler scripts follow symlinks when writing output files, allowing arbitrary file overwrites (CVE-2026-54230)
* abrt: unsanitized systemd journal content written to dump directory files enables content injection (CVE-2026-54231)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
CVE-2026-54228
A time-of-check time-of-use (TOCTOU) race condition was found in the abrt-dbus D-Bus service's SetElement method. Between dump directory creation and post-create event execution, any local user can call SetElement to write arbitrary text files into the root-owned dump directory, bypassing package validation and allowing crashes of unpackaged binaries to survive post-create processing.
CVE-2026-54229
A race condition was found in the abrt-dbus D-Bus service's ChownProblemDir method. ChownProblemDir opens the dump directory with DD_OPEN_READONLY and calls dd_chown to change ownership of all files to the caller's uid, succeeding even while post-create event handlers hold a write lock. This allows an attacker to gain filesystem-level control of the dump directory while privileged event scripts are still running.
CVE-2026-54230
A symlink following vulnerability was found in the ABRT post-create event handler scripts in libreport. Event scripts write output files using shell redirections without the O_NOFOLLOW flag. If the target file is replaced with a symlink, the shell process running as root follows the symlink and writes content to the symlink target, allowing arbitrary file overwrites on the system.
CVE-2026-54231
A content injection vulnerability was found in the ABRT post-create event handler scripts in libreport. The event script queries the systemd journal for log entries matching the crashed process and writes the results to files in the dump directory without sanitizing embedded control characters. A local user can inject arbitrary content into the journal output by embedding newline characters in syslog messages, controlling the content that root writes to dump directory files.
Update packages.
A time-of-check time-of-use (TOCTOU) race condition was found in the abrt-dbus D-Bus service's SetElement method. Between dump directory creation and post-create event execution, any local user can call SetElement to write arbitrary text files into the root-owned dump directory, bypassing package validation and allowing crashes of unpackaged binaries to survive post-create processing.
A race condition was found in the abrt-dbus D-Bus service's ChownProblemDir method. ChownProblemDir opens the dump directory with DD_OPEN_READONLY and calls dd_chown to change ownership of all files to the caller's uid, succeeding even while post-create event handlers hold a write lock. This allows an attacker to gain filesystem-level control of the dump directory while privileged event scripts are still running.
A symlink following vulnerability was found in the ABRT post-create event handler scripts in libreport. Event scripts write output files using shell redirections without the O_NOFOLLOW flag. If the target file is replaced with a symlink, the shell process running as root follows the symlink and writes content to the symlink target, allowing arbitrary file overwrites on the system.
A content injection vulnerability was found in the ABRT post-create event handler scripts in libreport. The event script queries the systemd journal for log entries matching the crashed process and writes the results to files in the dump directory without sanitizing embedded control characters. A local user can inject arbitrary content into the journal output by embedding newline characters in syslog messages, controlling the content that root writes to dump directory files.
N/A
SRPMS
- abrt-2.10.9-26.el8_10.ML.1.src.rpm
MD5: 928998bf2dec73ca462bf84d23044566
SHA-256: 9bbc25d06db870df7f602d46f5db002d8f68be6984c14c6e69157942943ca9e8
Size: 2.81 MB
Asianux Server 8 for x86_64
- abrt-2.10.9-26.el8_10.ML.1.x86_64.rpm
MD5: f0cd03af670a36d4d2ff82c6884c8376
SHA-256: b046f6deb31a7e81860e072ee7e26718bc97605d205785843f9421dfb9e4801b
Size: 541.63 kB - abrt-addon-ccpp-2.10.9-26.el8_10.ML.1.x86_64.rpm
MD5: f5697a897c90c4907ed3f4e8f21aaea0
SHA-256: a1e3ad7914b1c64c6ce8993c8bdb0da65ac69450f3617c6e0afabdaa65634859
Size: 146.71 kB - abrt-addon-coredump-helper-2.10.9-26.el8_10.ML.1.x86_64.rpm
MD5: 42673dacd4c389c9fab67a50f639fdeb
SHA-256: cae2c8804e3005879a24ec67b53263120912a965f9571db1fc500dd4725cdc1e
Size: 53.77 kB - abrt-addon-kerneloops-2.10.9-26.el8_10.ML.1.x86_64.rpm
MD5: 02ca23f143e7e11dc5748febabf6b702
SHA-256: df1f8540430c352a7311d86c3b65fdde86ecc48f8a9324d618a5ee5a7a265238
Size: 68.01 kB - abrt-addon-pstoreoops-2.10.9-26.el8_10.ML.1.x86_64.rpm
MD5: bf7b6a883cc0128dffa02999b8f45310
SHA-256: 8a6fe9c677a2b2c41383f252e3e76f91f39c74cdeab26f2bf68b8340216b62fe
Size: 46.39 kB - abrt-addon-vmcore-2.10.9-26.el8_10.ML.1.x86_64.rpm
MD5: 1aa2681e442c961f2635aa7f86b09956
SHA-256: f4949db2a7627fb98bb993e4a3f43c6df9acfea422a04714c0750a1df1319f64
Size: 57.79 kB - abrt-addon-xorg-2.10.9-26.el8_10.ML.1.x86_64.rpm
MD5: 288e3fd6cb9d5d904d070f842e857462
SHA-256: eb0d98ca2962f2f2fcf86a3682b7f6cc00828de03983329cd4c9f2755d403ab9
Size: 59.94 kB - abrt-cli-2.10.9-26.el8_10.ML.1.x86_64.rpm
MD5: 6e0b7636cff93d975584b1953c1404be
SHA-256: 55123815ae777116a215092427f4fcd3564abfc918365372d01f3d0fa6c90073
Size: 36.69 kB - abrt-cli-ng-2.10.9-26.el8_10.ML.1.x86_64.rpm
MD5: 5c43bbb03662d6b9f41dee116f66b092
SHA-256: 58600c957e2642885da40dfc1c87a9de6d4ea31c6bb0d99ee28d08eb4820234b
Size: 56.77 kB - abrt-console-notification-2.10.9-26.el8_10.ML.1.x86_64.rpm
MD5: b922d6c104959ac566971fc1a9236ddf
SHA-256: 5ba5c97fbc8bae21e5eca6da6ad8b5c95b0114c17135e8541ab50e2a161aa411
Size: 37.96 kB - abrt-dbus-2.10.9-26.el8_10.ML.1.x86_64.rpm
MD5: 87d3f900b83fe166f18ab87a73ba9c8d
SHA-256: 065616e654365bca1786e796a9f9fd6d6c3faf8ecfbeb3ba0265dfc86fe6ed65
Size: 104.20 kB - abrt-desktop-2.10.9-26.el8_10.ML.1.x86_64.rpm
MD5: 1bd9d6b557a55f7eb30385c5e6e2e9e2
SHA-256: 38cd88e282d77789f71797db177bff22b81853cba8a3107b47b56bd587eac6cb
Size: 36.76 kB - abrt-gui-2.10.9-26.el8_10.ML.1.x86_64.rpm
MD5: f7d32d48472632de23aebad107887d6d
SHA-256: 7e1c1e26d5dac73084dd5293204f654d2bbff160a1f076bc56ed773cc7f04622
Size: 136.42 kB - abrt-gui-libs-2.10.9-26.el8_10.ML.1.i686.rpm
MD5: 3186a5ec5fd02ed66ec90a29316657b7
SHA-256: 539f5276b2e6281b5d3e4096d04de9472759cf0d72c61cb52ad6a9dd5283d110
Size: 47.97 kB - abrt-gui-libs-2.10.9-26.el8_10.ML.1.x86_64.rpm
MD5: 2e00d7cfaf35a543497300b55e92be45
SHA-256: da01712801b4cbbb4a667b2bee95c0d5defd719f2bd6d64141711db477891003
Size: 47.28 kB - abrt-libs-2.10.9-26.el8_10.ML.1.i686.rpm
MD5: 2be39220b518b44e0f23344deac2f353
SHA-256: a8d31cf16350dfce42526eb18e573fe1ab13353c9c66c612033a644d8ce6f54c
Size: 67.83 kB - abrt-libs-2.10.9-26.el8_10.ML.1.x86_64.rpm
MD5: cc728cf50e5ce81305d1131309b0f497
SHA-256: ea6c8e596e49e1ff0110bb426fc10f52df2bb43c29932305b780748c2ea6cd65
Size: 66.57 kB - abrt-plugin-machine-id-2.10.9-26.el8_10.ML.1.x86_64.rpm
MD5: dc9866b7a22a962bb7b4d8ef3437c4fe
SHA-256: 9152c44ac0d013f05debefcc418c807c02c8a58821f8945d4dfba786db6491f8
Size: 40.02 kB - abrt-plugin-sosreport-2.10.9-26.el8_10.ML.1.x86_64.rpm
MD5: b357aa22de78dd082edc02fb779db37a
SHA-256: a76543603d467a9871b6644b8d4c17a82d087b0cf8a3de5b7c9054ad8c61dab1
Size: 37.89 kB - abrt-tui-2.10.9-26.el8_10.ML.1.x86_64.rpm
MD5: bb3cb7243c0f7c99444e7ef5dd4eac6f
SHA-256: 7dc74dde2d885cbefb4b19dcb05dbc9677fef2ee70a729fcab19644fa3bc5a6a
Size: 50.05 kB