Executive brief
A security flaw exists in the Automatic Bug Reporting Tool (ABRT), a service used in Linux environments to collect and analyze software crash data. An attacker with local access can exploit a timing issue to take control of crash report directories while the system is still processing them with high privileges. This could allow an unauthorized user to manipulate system files, potentially leading to a full system compromise or data theft.
Technical details
A race condition (CWE-362) exists in the abrt-dbus D-Bus service's ChownProblemDir method. The vulnerability stems from ChownProblemDir opening dump directories using the DD_OPEN_READONLY flag, which fails to respect existing write locks held by post-create event handlers. By invoking this method, a local attacker can trigger dd_chown to change ownership of the directory's contents to their own UID. This allows the attacker to manipulate files (such as creating symlinks or deleting data) within the directory while privileged event shell processes are still running under the root-privileged abrt_handle_event_t SELinux domain. Exploitation requires local access and precise timing to interact with the D-Bus service during active event processing.
Affected products
- Red Hat abrt-dbus unspecified
Timeline
- 2026-06-12: disclosed: Reported via Red Hat Bugzilla
- 2026-06-13: advisory: NVD publication date