High severity7.0NVD Advisory· Published Jun 13, 2026· Updated Aug 26, 2026
CVE-2026-54230
CVE-2026-54230
Description
A symlink following vulnerability was found in the ABRT post-create event handler scripts in libreport. Event scripts write output files using shell redirections without the O_NOFOLLOW flag. If the target file is replaced with a symlink, the shell process running as root follows the symlink and writes content to the symlink target, allowing arbitrary file overwrites on the system.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
29- cpe:2.3:a:abrt_project:abrt:*:*:*:*:*:*:*:*
cpe:2.3:o:fedoraproject:fedora:43:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:o:fedoraproject:fedora:43:*:*:*:*:*:*:*
- cpe:2.3:o:fedoraproject:fedora:44:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:7.0:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:o:redhat:enterprise_linux:7.0:*:*:*:*:*:*:*
- cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:*:*:*:*
- osv-coords22 versionspkg:rpm/almalinux/abrtpkg:rpm/almalinux/abrt-addon-ccpppkg:rpm/almalinux/abrt-addon-coredump-helperpkg:rpm/almalinux/abrt-addon-kerneloopspkg:rpm/almalinux/abrt-addon-pstoreoopspkg:rpm/almalinux/abrt-addon-vmcorepkg:rpm/almalinux/abrt-addon-xorgpkg:rpm/almalinux/abrt-clipkg:rpm/almalinux/abrt-cli-ngpkg:rpm/almalinux/abrt-console-notificationpkg:rpm/almalinux/abrt-dbuspkg:rpm/almalinux/abrt-desktoppkg:rpm/almalinux/abrt-guipkg:rpm/almalinux/abrt-gui-libspkg:rpm/almalinux/abrt-libspkg:rpm/almalinux/abrt-plugin-machine-idpkg:rpm/almalinux/abrt-plugin-sosreportpkg:rpm/almalinux/abrt-tuipkg:rpm/almalinux/python3-abrtpkg:rpm/almalinux/python3-abrt-addonpkg:rpm/almalinux/python3-abrt-container-addonpkg:rpm/almalinux/python3-abrt-doc
< 2.10.9-26.el8_10.alma.1+ 21 more
- (no CPE)range: < 2.10.9-26.el8_10.alma.1
- (no CPE)range: < 2.10.9-26.el8_10.alma.1
- (no CPE)range: < 2.10.9-26.el8_10.alma.1
- (no CPE)range: < 2.10.9-26.el8_10.alma.1
- (no CPE)range: < 2.10.9-26.el8_10.alma.1
- (no CPE)range: < 2.10.9-26.el8_10.alma.1
- (no CPE)range: < 2.10.9-26.el8_10.alma.1
- (no CPE)range: < 2.10.9-26.el8_10.alma.1
- (no CPE)range: < 2.10.9-26.el8_10.alma.1
- (no CPE)range: < 2.10.9-26.el8_10.alma.1
- (no CPE)range: < 2.10.9-26.el8_10.alma.1
- (no CPE)range: < 2.10.9-26.el8_10.alma.1
- (no CPE)range: < 2.10.9-26.el8_10.alma.1
- (no CPE)range: < 2.10.9-26.el8_10.alma.1
- (no CPE)range: < 2.10.9-26.el8_10.alma.1
- (no CPE)range: < 2.10.9-26.el8_10.alma.1
- (no CPE)range: < 2.10.9-26.el8_10.alma.1
- (no CPE)range: < 2.10.9-26.el8_10.alma.1
- (no CPE)range: < 2.10.9-26.el8_10.alma.1
- (no CPE)range: < 2.10.9-26.el8_10.alma.1
- (no CPE)range: < 2.10.9-26.el8_10.alma.1
- (no CPE)range: < 2.10.9-26.el8_10.alma.1
Patches
Vulnerability mechanics
References
4- access.redhat.com/security/cve/CVE-2026-54230nvdVendor Advisory
- bugzilla.redhat.com/show_bug.cginvdIssue TrackingVendor Advisory
- access.redhat.com/errata/RHSA-2026:54272nvd
- security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-54230.jsonnvd
News mentions
0No linked articles in our index yet.