PT-2026-49076 · Libreport+1 · Libreport+1

·

CVE-2026-54231

·

Published

2026-06-13

·

Updated

2026-08-26

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions libreport (affected versions not specified)
Description A content injection issue exists in the ABRT post-create event handler scripts within libreport. The event script retrieves log entries from the systemd journal for crashed processes and writes them to files in the dump directory. Because embedded control characters are not sanitized, a local user can inject arbitrary content into the journal output by including newline characters in syslog messages, allowing them to control the content written to dump directory files by the root user.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Special Elements Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2026:54272
AZL-90101
CVE-2026-54231

Affected Products

Rocky Linux
Libreport