RHSA-2026:48864: Important: abrt security update
Important: abrt security update
Other sources
The Automatic Bug Reporting Tool (ABRT) recognizes defects in applications and creates bug reports that help maintainers fix the defects. ABRT uses a plug-in system to extend its functionality. Security Fix(es): abrt: TOCTOU race condition in abrt-dbus SetElement allows arbitrary file writes to dump directories (CVE-2026-54228) abrt: ChownProblemDir succeeds during active post-create event processing due to inadequate locking (CVE-2026-54229) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
— Red Hat
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/abrtto a version that resolves this vulnerability.Fixed in 2.10.9-25.el8_8.1 - Upgrade
Upgrade
redhat/abrt-addon-ccppto a version that resolves this vulnerability.Fixed in 2.10.9-25.el8_8.1 - Upgrade
Upgrade
redhat/abrt-addon-ccpp-debuginfoto a version that resolves this vulnerability.Fixed in 2.10.9-25.el8_8.1 - Upgrade
Upgrade
redhat/abrt-addon-coredump-helperto a version that resolves this vulnerability.Fixed in 2.10.9-25.el8_8.1 - Upgrade
Upgrade
redhat/abrt-addon-coredump-helper-debuginfoto a version that resolves this vulnerability.Fixed in 2.10.9-25.el8_8.1 - Upgrade
Upgrade
redhat/abrt-addon-kerneloopsto a version that resolves this vulnerability.Fixed in 2.10.9-25.el8_8.1 - Upgrade
Upgrade
redhat/abrt-addon-kerneloops-debuginfoto a version that resolves this vulnerability.Fixed in 2.10.9-25.el8_8.1 - Upgrade
Upgrade
redhat/abrt-addon-pstoreoopsto a version that resolves this vulnerability.Fixed in 2.10.9-25.el8_8.1 - Upgrade
Upgrade
redhat/abrt-addon-pstoreoops-debuginfoto a version that resolves this vulnerability.Fixed in 2.10.9-25.el8_8.1 - Upgrade
Upgrade
redhat/abrt-addon-upload-watch-debuginfoto a version that resolves this vulnerability.Fixed in 2.10.9-25.el8_8.1 - Upgrade
Upgrade
redhat/abrt-addon-vmcoreto a version that resolves this vulnerability.Fixed in 2.10.9-25.el8_8.1 - Upgrade
Upgrade
redhat/abrt-addon-xorgto a version that resolves this vulnerability.Fixed in 2.10.9-25.el8_8.1 - Upgrade
Upgrade
redhat/abrt-addon-xorg-debuginfoto a version that resolves this vulnerability.Fixed in 2.10.9-25.el8_8.1 - Upgrade
Upgrade
redhat/abrt-atomic-debuginfoto a version that resolves this vulnerability.Fixed in 2.10.9-25.el8_8.1 - Upgrade
Upgrade
redhat/abrt-clito a version that resolves this vulnerability.Fixed in 2.10.9-25.el8_8.1 - Upgrade
Upgrade
redhat/abrt-cli-ngto a version that resolves this vulnerability.Fixed in 2.10.9-25.el8_8.1 - Upgrade
Upgrade
redhat/abrt-console-notificationto a version that resolves this vulnerability.Fixed in 2.10.9-25.el8_8.1 - Upgrade
Upgrade
redhat/abrt-dbusto a version that resolves this vulnerability.Fixed in 2.10.9-25.el8_8.1 - Upgrade
Upgrade
redhat/abrt-dbus-debuginfoto a version that resolves this vulnerability.Fixed in 2.10.9-25.el8_8.1 - Upgrade
Upgrade
redhat/abrt-debuginfoto a version that resolves this vulnerability.Fixed in 2.10.9-25.el8_8.1 - Upgrade
Upgrade
redhat/abrt-debugsourceto a version that resolves this vulnerability.Fixed in 2.10.9-25.el8_8.1 - Upgrade
Upgrade
redhat/abrt-desktopto a version that resolves this vulnerability.Fixed in 2.10.9-25.el8_8.1 - Upgrade
Upgrade
redhat/abrt-guito a version that resolves this vulnerability.Fixed in 2.10.9-25.el8_8.1 - Upgrade
Upgrade
redhat/abrt-gui-debuginfoto a version that resolves this vulnerability.Fixed in 2.10.9-25.el8_8.1 - Upgrade
Upgrade
redhat/abrt-gui-libsto a version that resolves this vulnerability.Fixed in 2.10.9-25.el8_8.1 - Upgrade
Upgrade
redhat/abrt-gui-libs-debuginfoto a version that resolves this vulnerability.Fixed in 2.10.9-25.el8_8.1 - Upgrade
Upgrade
redhat/abrt-libsto a version that resolves this vulnerability.Fixed in 2.10.9-25.el8_8.1 - Upgrade
Upgrade
redhat/abrt-libs-debuginfoto a version that resolves this vulnerability.Fixed in 2.10.9-25.el8_8.1 - Upgrade
Upgrade
redhat/abrt-plugin-machine-idto a version that resolves this vulnerability.Fixed in 2.10.9-25.el8_8.1 - Upgrade
Upgrade
redhat/abrt-plugin-sosreportto a version that resolves this vulnerability.Fixed in 2.10.9-25.el8_8.1 - Upgrade
Upgrade
redhat/abrt-retrace-client-debuginfoto a version that resolves this vulnerability.Fixed in 2.10.9-25.el8_8.1 - Upgrade
Upgrade
redhat/abrt-tuito a version that resolves this vulnerability.Fixed in 2.10.9-25.el8_8.1 - Upgrade
Upgrade
redhat/abrt-tui-debuginfoto a version that resolves this vulnerability.Fixed in 2.10.9-25.el8_8.1 - Upgrade
Upgrade
redhat/python3-abrtto a version that resolves this vulnerability.Fixed in 2.10.9-25.el8_8.1 - Upgrade
Upgrade
redhat/python3-abrt-addonto a version that resolves this vulnerability.Fixed in 2.10.9-25.el8_8.1 - Upgrade
Upgrade
redhat/python3-abrt-container-addonto a version that resolves this vulnerability.Fixed in 2.10.9-25.el8_8.1 - Upgrade
Upgrade
redhat/python3-abrt-debuginfoto a version that resolves this vulnerability.Fixed in 2.10.9-25.el8_8.1 - Upgrade
Upgrade
redhat/python3-abrt-docto a version that resolves this vulnerability.Fixed in 2.10.9-25.el8_8.1 - Upgrade
Upgrade
abrtto a version that resolves this vulnerability.Patch CVE-2026-54228 - Upgrade
Upgrade
abrtto a version that resolves this vulnerability.Patch CVE-2026-54229 - Compensating control
Use the vendor advisory referenced as "ABRT security update" (Red Hat article 11258) to apply the described security changes, including the fixes for CVE-2026-54228 and CVE-2026-54229.
Event History
Frequently Asked Questions
What is the severity of RHSA-2026:48864?
The severity of RHSA-2026:48864 is classified as high with a score of 7.
What is the main issue addressed in RHSA-2026:48864?
RHSA-2026:48864 addresses a TOCTOU race condition in the Automatic Bug Reporting Tool (ABRT) components.
How do I fix RHSA-2026:48864?
To fix RHSA-2026:48864, update your ABRT packages to the latest version provided by Red Hat.
Which software packages are affected by RHSA-2026:48864?
Affected software packages include redhat/abrt and its various debug add-ons like abrt-addon-ccpp-debuginfo.
Why is it important to address RHSA-2026:48864?
Addressing RHSA-2026:48864 is important as it mitigates potential security risks caused by the identified race condition in ABRT.