Race Condition Vulnerability in abrt-dbus D-Bus Service Affects Red Hat Systems
CVE-2026-54228
Key Information:
- Vendor
Red Hat
- Status
- Vendor
- CVE Published:
- 13 June 2026
What is CVE-2026-54228?
A race condition vulnerability exists in the abrt-dbus D-Bus service's SetElement method on Red Hat systems. This flaw occurs during the process of creating a dump directory and executing post-create events. Malicious local users can exploit this by invoking SetElement, allowing them to write arbitrary text files into a directory that should be restricted. This capability undermines package validation mechanisms, enabling the potential for crashes of unpackaged binaries to persist through post-create actions.
Affected Version(s)
Red Hat Enterprise Linux 7 Extended Lifecycle Support 0:2.1.11-61.el7_9
Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support 0:2.10.9-25.el8_4.1
Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On 0:2.10.9-25.el8_4.1
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved