A time-of-check time-of-use (TOCTOU) race condition was...
High severity
Unreviewed
Published
Jun 13, 2026
to the GitHub Advisory Database
Description
Published by the National Vulnerability Database
Jun 13, 2026
Published to the GitHub Advisory Database
Jun 13, 2026
A time-of-check time-of-use (TOCTOU) race condition was found in the abrt-dbus D-Bus service's SetElement method. Between dump directory creation and post-create event execution, any local user can call SetElement to write arbitrary text files into the root-owned dump directory, bypassing package validation and allowing crashes of unpackaged binaries to survive post-create processing.
References