PT-2026-49075 · Libreport+1 · Libreport+1

·

CVE-2026-54230

·

Published

2026-06-13

·

Updated

2026-08-26

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions libreport (affected versions not specified)
Description A symlink following issue exists in the ABRT post-create event handler scripts. These scripts write output files using shell redirections without the O NOFOLLOW flag (a flag that prevents a file from being opened if it is a symbolic link). If a target file is replaced with a symlink, the shell process running with root privileges follows the link and writes content to the target, enabling arbitrary file overwrites on the system.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

LPE

Link Following

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2026:54272
AZL-90104
CVE-2026-54230

Affected Products

Rocky Linux
Libreport