Race Condition Vulnerability in abrt-dbus ChownProblemDir Method Affecting Red Hat
CVE-2026-54229

7HIGH

What is CVE-2026-54229?

A race condition vulnerability exists in the abrt-dbus D-Bus service's ChownProblemDir method. This vulnerability allows an attacker to manipulate filesystem ownership of the dump directory while privileged event scripts are still executing. By exploiting this flaw, unauthorized users could potentially gain control over sensitive files, as the method incorrectly handles file ownership when certain write locks are active. The flaw highlights potential risks in concurrent operations within the service and requires immediate attention to prevent misuse.

Affected Version(s)

Red Hat Enterprise Linux 7 Extended Lifecycle Support 0:2.1.11-61.el7_9

Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support 0:2.10.9-25.el8_4.1

Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On 0:2.10.9-25.el8_4.1

References

CVSS V3.1

Score:
7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Red Hat would like to thank Red Team (Deutsche Telekom Security GmbH) for reporting this issue.
.