← العودة للجدول
CVE-2026-54230
CVE-2026-54230 — A symlink following vulnerability was found in the ABRT post-create event handle
📅 2026-06-13
🟠 High 🔥 No NVD Exploit Vulnerability CVSS 7

📋 الوصف الكامل

A symlink following vulnerability was found in the ABRT post-create event handler scripts in libreport. Event scripts write output files using shell redirections without the O_NOFOLLOW flag. If the target file is replaced with a symlink, the shell process running as root follows the symlink and writes content to the symlink target, allowing arbitrary file overwrites on the system.

💻 الأنظمة المتأثرة

⚠️ نوع التهديد

Exploit

🔗 CVE ID

CVE-2026-54230

📡 المصدر

NVD

✅ الحلول والتخفيف

Refer to CVE-2026-54230 NVD advisory

🔗 المصدر الأصلي ← 📘 NVD ← ⚡ CISA KEV ←