Junglewise Threat Intelligence

CVE-2026-54228: Red Hat abrt TOCTOU race condition in abrt-dbus SetElement

CVE-2026-54228 · Severity: high · CVSS 7.8 · Published 2026-06-13

Technologies: Red Hat Abrt. Vendors: Red Hat.

Executive brief

A security vulnerability has been identified in the Automatic Bug Reporting Tool (ABRT), a service used in Linux environments to collect and analyze software crash data. A local user can exploit a timing flaw to inject unauthorized data into system crash reports before they are processed by the system. This could allow an attacker to bypass security validations, potentially leading to unauthorized file modifications or the ability to hide malicious activity within system logs.

Technical details

A TOCTOU race condition exists in the abrt-dbus D-Bus service's SetElement method. The vulnerability occurs in the window between the creation of a dump directory by abrtd and the execution of post-create events. During this interval, a local user can invoke SetElement to write arbitrary text files into the root-owned dump directory. The service's access check (dd_accessible_by_uid) relies on a UID element within the directory that matches the caller's UID if they triggered the initial crash. By exploiting this race, an attacker can modify elements like 'component' to bypass package validation (abrt-action-save-package-data), ensuring that crashes from unpackaged or malicious binaries persist through post-create processing.

Affected products

  • Red Hat abrt unspecified

Timeline

  • 2026-06-12: disclosed: Initial report via Red Hat Bugzilla
  • 2026-06-13: advisory: NVD publication date

References

Related threats