VYPR

rpm package

almalinux/abrt-addon-ccpp

pkg:rpm/almalinux/abrt-addon-ccpp

Vulnerabilities (5)

  • CVE-2026-54231MedJun 13, 2026
    affected < 2.10.9-26.el8_10.alma.1fixed 2.10.9-26.el8_10.alma.1

    A content injection vulnerability was found in the ABRT post-create event handler scripts in libreport. The event script queries the systemd journal for log entries matching the crashed process and writes the results to files in the dump directory without sanitizing embedded cont

  • CVE-2026-54230HigJun 13, 2026
    affected < 2.10.9-26.el8_10.alma.1fixed 2.10.9-26.el8_10.alma.1

    A symlink following vulnerability was found in the ABRT post-create event handler scripts in libreport. Event scripts write output files using shell redirections without the O_NOFOLLOW flag. If the target file is replaced with a symlink, the shell process running as root follows

  • CVE-2026-54229HigJun 13, 2026
    affected < 2.10.9-26.el8_10.alma.1fixed 2.10.9-26.el8_10.alma.1

    A race condition was found in the abrt-dbus D-Bus service's ChownProblemDir method. ChownProblemDir opens the dump directory with DD_OPEN_READONLY and calls dd_chown to change ownership of all files to the caller's uid, succeeding even while post-create event handlers hold a writ

  • CVE-2026-54228HigJun 13, 2026
    affected < 2.10.9-26.el8_10.alma.1fixed 2.10.9-26.el8_10.alma.1

    A time-of-check time-of-use (TOCTOU) race condition was found in the abrt-dbus D-Bus service's SetElement method. Between dump directory creation and post-create event execution, any local user can call SetElement to write arbitrary text files into the root-owned dump directory,

  • CVE-2025-12744HigDec 3, 2025
    affected < 2.10.9-25.el8_10.alma.1fixed 2.10.9-25.el8_10.alma.1

    A flaw was found in the ABRT daemon’s handling of user-supplied mount information.ABRT copies up to 12 characters from an untrusted input and places them directly into a shell command (docker inspect %s) without proper validation. An unprivileged local user can craft a payload th