PT-2026-49074 · Red Hat · Red Hat Enterprise Linux 6+2

Published

2026-06-13

·

Updated

2026-06-13

·

CVE-2026-54229

CVSS v3.1

7.0

High

VectorAV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
A race condition was found in the abrt-dbus D-Bus service's ChownProblemDir method. ChownProblemDir opens the dump directory with DD OPEN READONLY and calls dd chown to change ownership of all files to the caller's uid, succeeding even while post-create event handlers hold a write lock. This allows an attacker to gain filesystem-level control of the dump directory while privileged event scripts are still running.

Fix

Race Condition

Weakness Enumeration

Related Identifiers

CVE-2026-54229

Affected Products

Red Hat Enterprise Linux 6
Red Hat Enterprise Linux 7
Red Hat Enterprise Linux 8