Race Condition Vulnerability in abrt-dbus D-Bus Service Affects Red Hat Systems
CVE-2026-54228

7.8HIGH

What is CVE-2026-54228?

A race condition vulnerability exists in the abrt-dbus D-Bus service's SetElement method on Red Hat systems. This flaw occurs during the process of creating a dump directory and executing post-create events. Malicious local users can exploit this by invoking SetElement, allowing them to write arbitrary text files into a directory that should be restricted. This capability undermines package validation mechanisms, enabling the potential for crashes of unpackaged binaries to persist through post-create actions.

Affected Version(s)

Red Hat Enterprise Linux 7 Extended Lifecycle Support 0:2.1.11-61.el7_9

Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support 0:2.10.9-25.el8_4.1

Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On 0:2.10.9-25.el8_4.1

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Red Hat would like to thank Red Team (Deutsche Telekom Security GmbH) for reporting this issue.
.