rpm package
almalinux/python3-abrt-doc
pkg:rpm/almalinux/python3-abrt-doc
Vulnerabilities (5)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2026-54231 | Med | 5.5 | < 2.10.9-26.el8_10.alma.1 | 2.10.9-26.el8_10.alma.1 | Jun 13, 2026 | A content injection vulnerability was found in the ABRT post-create event handler scripts in libreport. The event script queries the systemd journal for log entries matching the crashed process and writes the results to files in the dump directory without sanitizing embedded cont | |
| CVE-2026-54230 | Hig | 7.0 | < 2.10.9-26.el8_10.alma.1 | 2.10.9-26.el8_10.alma.1 | Jun 13, 2026 | A symlink following vulnerability was found in the ABRT post-create event handler scripts in libreport. Event scripts write output files using shell redirections without the O_NOFOLLOW flag. If the target file is replaced with a symlink, the shell process running as root follows | |
| CVE-2026-54229 | Hig | 7.0 | < 2.10.9-26.el8_10.alma.1 | 2.10.9-26.el8_10.alma.1 | Jun 13, 2026 | A race condition was found in the abrt-dbus D-Bus service's ChownProblemDir method. ChownProblemDir opens the dump directory with DD_OPEN_READONLY and calls dd_chown to change ownership of all files to the caller's uid, succeeding even while post-create event handlers hold a writ | |
| CVE-2026-54228 | Hig | 7.8 | < 2.10.9-26.el8_10.alma.1 | 2.10.9-26.el8_10.alma.1 | Jun 13, 2026 | A time-of-check time-of-use (TOCTOU) race condition was found in the abrt-dbus D-Bus service's SetElement method. Between dump directory creation and post-create event execution, any local user can call SetElement to write arbitrary text files into the root-owned dump directory, | |
| CVE-2025-12744 | Hig | 8.8 | < 2.10.9-25.el8_10.alma.1 | 2.10.9-25.el8_10.alma.1 | Dec 3, 2025 | A flaw was found in the ABRT daemon’s handling of user-supplied mount information.ABRT copies up to 12 characters from an untrusted input and places them directly into a shell command (docker inspect %s) without proper validation. An unprivileged local user can craft a payload th |
- affected < 2.10.9-26.el8_10.alma.1fixed 2.10.9-26.el8_10.alma.1
A content injection vulnerability was found in the ABRT post-create event handler scripts in libreport. The event script queries the systemd journal for log entries matching the crashed process and writes the results to files in the dump directory without sanitizing embedded cont
- affected < 2.10.9-26.el8_10.alma.1fixed 2.10.9-26.el8_10.alma.1
A symlink following vulnerability was found in the ABRT post-create event handler scripts in libreport. Event scripts write output files using shell redirections without the O_NOFOLLOW flag. If the target file is replaced with a symlink, the shell process running as root follows
- affected < 2.10.9-26.el8_10.alma.1fixed 2.10.9-26.el8_10.alma.1
A race condition was found in the abrt-dbus D-Bus service's ChownProblemDir method. ChownProblemDir opens the dump directory with DD_OPEN_READONLY and calls dd_chown to change ownership of all files to the caller's uid, succeeding even while post-create event handlers hold a writ
- affected < 2.10.9-26.el8_10.alma.1fixed 2.10.9-26.el8_10.alma.1
A time-of-check time-of-use (TOCTOU) race condition was found in the abrt-dbus D-Bus service's SetElement method. Between dump directory creation and post-create event execution, any local user can call SetElement to write arbitrary text files into the root-owned dump directory,
- affected < 2.10.9-25.el8_10.alma.1fixed 2.10.9-25.el8_10.alma.1
A flaw was found in the ABRT daemon’s handling of user-supplied mount information.ABRT copies up to 12 characters from an untrusted input and places them directly into a shell command (docker inspect %s) without proper validation. An unprivileged local user can craft a payload th