PT-2026-49074 · Abrt-Dbus · Abrt-Dbus

·

CVE-2026-54229

·

Published

2026-06-13

·

Updated

2026-06-16

CVSS v3.1

7.0

High

VectorAV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions abrt-dbus (affected versions not specified)
Description A race condition exists in the ChownProblemDir method of the abrt-dbus D-Bus service. The ChownProblemDir method opens the dump directory using DD OPEN READONLY and executes dd chown() to change the ownership of all files to the user ID of the caller. This process can succeed even when post-create event handlers maintain a write lock, enabling an attacker to obtain filesystem-level control of the dump directory while privileged event scripts are still active.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Race Condition

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-54229

Affected Products

Abrt-Dbus