Fedora Account System
Red Hat Associate
Red Hat Customer
A race condition was found in the abrt-dbus D-Bus service's ChownProblemDir method. ChownProblemDir opens the dump directory with DD_OPEN_READONLY (which does not require a write lock) and calls dd_chown to change ownership of all files to the caller's uid. This succeeds even while post-create event handlers hold a write lock on the dump directory, because the read-only open does not conflict with the write lock. After ChownProblemDir, the attacker gains direct filesystem-level access to the dump directory (can delete files, create symlinks, etc.) while the already-running event shell process continues executing with root privileges in the abrt_handle_event_t SELinux domain.
This issue has been addressed in the following products: Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On Via RHSA-2026:48819 https://access.redhat.com/errata/RHSA-2026:48819
This issue has been addressed in the following products: Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On Via RHSA-2026:48865 https://access.redhat.com/errata/RHSA-2026:48865
This issue has been addressed in the following products: Red Hat Enterprise Linux 7 Extended Lifecycle Support Via RHSA-2026:48866 https://access.redhat.com/errata/RHSA-2026:48866
This issue has been addressed in the following products: Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions Red Hat Enterprise Linux 8.8 Telecommunications Update Service Via RHSA-2026:48864 https://access.redhat.com/errata/RHSA-2026:48864
This issue has been addressed in the following products: Red Hat Enterprise Linux 8 Via RHSA-2026:54272 https://access.redhat.com/errata/RHSA-2026:54272