Content Injection Vulnerability in ABRT by Red Hat
CVE-2026-54231
5.5MEDIUM
What is CVE-2026-54231?
A content injection vulnerability has been identified in the ABRT post-create event handler scripts within the libreport package. This vulnerability arises due to the script's interaction with the systemd journal to retrieve log entries associated with crashed processes. The script fails to properly sanitize control characters, allowing a local user to manipulate the journal output by injecting arbitrary content through newline characters embedded in syslog messages. As a result, this can control the contents written by root into files located in the dump directory, potentially leading to unauthorized information disclosure or further exploitation.
References
CVSS V3.1
Score:
5.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Red Hat would like to thank Red Team (Deutsche Telekom Security GmbH) for reporting this issue.