A symlink following vulnerability was found in the ABRT...
High severity
Unreviewed
Published
Jun 13, 2026
to the GitHub Advisory Database
•
Updated Jun 13, 2026
Description
Published by the National Vulnerability Database
Jun 13, 2026
Published to the GitHub Advisory Database
Jun 13, 2026
Last updated
Jun 13, 2026
A symlink following vulnerability was found in the ABRT post-create event handler scripts in libreport. Event scripts write output files using shell redirections without the O_NOFOLLOW flag. If the target file is replaced with a symlink, the shell process running as root follows the symlink and writes content to the symlink target, allowing arbitrary file overwrites on the system.
References