CVE-2026-54230
Red Hat Red Hat Enterprise Linux 6, Red Hat Enterprise Linux 7, Red Hat Enterprise Linux 8
A symlink following vulnerability was found in the ABRT post-create event handler scripts in libreport. Event scripts write output files using shell redirections without the O_NOFOLLOW flag. If the target file is replaced with a symlink, the shell process running as root follows the symlink and writes content to the symlink target, allowing arbitrary file overwrites on the system.
- CVSS
- 7.8
- EPSS
- 0.14% 3.76% percentile
- CISA KEV
- Not listed
- Published
- 2026.06.13