CVE-2026-54231

EUVD-2026-36640
A content injection vulnerability was found in the ABRT post-create event handler scripts in libreport. The event script queries the systemd journal for log entries matching the crashed process and writes the results to files in the dump directory without sanitizing embedded control characters. A local user can inject arbitrary content into the journal output by embedding newline characters in syslog messages, controlling the content that root writes to dump directory files.
Injection
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
5.5 MEDIUM
LOCAL
LOW
LOW
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 7.34%
Affected Products (NVD)
VendorProductVersion
redhatautomatic_bug_reporting_tool
*
redhatenterprise_linux
7.0
redhatenterprise_linux
8.0
𝑥
= Vulnerable software versions
Red Hat logo
Red Hat Enterprise Linux Releases
Red Hat Product
Release
abrt
RHEL 8
0:2.10.9-26.el8_10
fixed
abrt-addon-ccpp
RHEL 8
0:2.10.9-26.el8_10
fixed
abrt-addon-coredump-helper
RHEL 8
0:2.10.9-26.el8_10
fixed
abrt-addon-kerneloops
RHEL 8
0:2.10.9-26.el8_10
fixed
abrt-addon-pstoreoops
RHEL 8
0:2.10.9-26.el8_10
fixed
abrt-addon-vmcore
RHEL 8
0:2.10.9-26.el8_10
fixed
abrt-addon-xorg
RHEL 8
0:2.10.9-26.el8_10
fixed
abrt-cli
RHEL 8
0:2.10.9-26.el8_10
fixed
abrt-cli-ng
RHEL 8
0:2.10.9-26.el8_10
fixed
abrt-console-notification
RHEL 8
0:2.10.9-26.el8_10
fixed
abrt-dbus
RHEL 8
0:2.10.9-26.el8_10
fixed
abrt-desktop
RHEL 8
0:2.10.9-26.el8_10
fixed
abrt-gui
RHEL 8
0:2.10.9-26.el8_10
fixed
abrt-gui-libs
RHEL 8
0:2.10.9-26.el8_10
fixed
abrt-libs
RHEL 8
0:2.10.9-26.el8_10
fixed
abrt-plugin-machine-id
RHEL 8
0:2.10.9-26.el8_10
fixed
abrt-plugin-sosreport
RHEL 8
0:2.10.9-26.el8_10
fixed
abrt-tui
RHEL 8
0:2.10.9-26.el8_10
fixed
python3-abrt
RHEL 8
0:2.10.9-26.el8_10
fixed
python3-abrt-addon
RHEL 8
0:2.10.9-26.el8_10
fixed
python3-abrt-container-addon
RHEL 8
0:2.10.9-26.el8_10
fixed
python3-abrt-doc
RHEL 8
0:2.10.9-26.el8_10
fixed