RHSA-2026:48866: Important: abrt security update
Important: abrt security update
Other sources
The Automatic Bug Reporting Tool (ABRT) recognizes defects in applications and creates bug reports that help maintainers fix the defects. ABRT uses a plug-in system to extend its functionality. Security Fix(es): abrt: TOCTOU race condition in abrt-dbus SetElement allows arbitrary file writes to dump directories (CVE-2026-54228) abrt: ChownProblemDir succeeds during active post-create event processing due to inadequate locking (CVE-2026-54229) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
— Red Hat
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/abrtto a version that resolves this vulnerability.Fixed in 2.1.11-61.el7_9 - Upgrade
Upgrade
redhat/abrt-addon-ccppto a version that resolves this vulnerability.Fixed in 2.1.11-61.el7_9 - Upgrade
Upgrade
redhat/abrt-addon-kerneloopsto a version that resolves this vulnerability.Fixed in 2.1.11-61.el7_9 - Upgrade
Upgrade
redhat/abrt-addon-pstoreoopsto a version that resolves this vulnerability.Fixed in 2.1.11-61.el7_9 - Upgrade
Upgrade
redhat/abrt-addon-pythonto a version that resolves this vulnerability.Fixed in 2.1.11-61.el7_9 - Upgrade
Upgrade
redhat/abrt-addon-upload-watchto a version that resolves this vulnerability.Fixed in 2.1.11-61.el7_9 - Upgrade
Upgrade
redhat/abrt-addon-vmcoreto a version that resolves this vulnerability.Fixed in 2.1.11-61.el7_9 - Upgrade
Upgrade
redhat/abrt-addon-xorgto a version that resolves this vulnerability.Fixed in 2.1.11-61.el7_9 - Upgrade
Upgrade
redhat/abrt-clito a version that resolves this vulnerability.Fixed in 2.1.11-61.el7_9 - Upgrade
Upgrade
redhat/abrt-console-notificationto a version that resolves this vulnerability.Fixed in 2.1.11-61.el7_9 - Upgrade
Upgrade
redhat/abrt-dbusto a version that resolves this vulnerability.Fixed in 2.1.11-61.el7_9 - Upgrade
Upgrade
redhat/abrt-debuginfoto a version that resolves this vulnerability.Fixed in 2.1.11-61.el7_9 - Upgrade
Upgrade
redhat/abrt-desktopto a version that resolves this vulnerability.Fixed in 2.1.11-61.el7_9 - Upgrade
Upgrade
redhat/abrt-develto a version that resolves this vulnerability.Fixed in 2.1.11-61.el7_9 - Upgrade
Upgrade
redhat/abrt-guito a version that resolves this vulnerability.Fixed in 2.1.11-61.el7_9 - Upgrade
Upgrade
redhat/abrt-gui-develto a version that resolves this vulnerability.Fixed in 2.1.11-61.el7_9 - Upgrade
Upgrade
redhat/abrt-gui-libsto a version that resolves this vulnerability.Fixed in 2.1.11-61.el7_9 - Upgrade
Upgrade
redhat/abrt-libsto a version that resolves this vulnerability.Fixed in 2.1.11-61.el7_9 - Upgrade
Upgrade
redhat/abrt-pythonto a version that resolves this vulnerability.Fixed in 2.1.11-61.el7_9 - Upgrade
Upgrade
redhat/abrt-python-docto a version that resolves this vulnerability.Fixed in 2.1.11-61.el7_9 - Upgrade
Upgrade
redhat/abrt-retrace-clientto a version that resolves this vulnerability.Fixed in 2.1.11-61.el7_9 - Upgrade
Upgrade
redhat/abrt-tuito a version that resolves this vulnerability.Fixed in 2.1.11-61.el7_9 - Upgrade
Upgrade
abrtto a version that resolves this vulnerability.Patch CVE-2026-54228 - Upgrade
Upgrade
abrtto a version that resolves this vulnerability.Patch CVE-2026-54229
Event History
Frequently Asked Questions
What is the severity of RHSA-2026:48866?
The severity of RHSA-2026:48866 is high with a score of 7.
What does RHSA-2026:48866 address?
RHSA-2026:48866 addresses a security update for the ABRT component in Red Hat Enterprise Linux.
How do I fix RHSA-2026:48866?
To fix RHSA-2026:48866, you should update your ABRT package to the latest version provided in the update.
Which systems are affected by RHSA-2026:48866?
RHSA-2026:48866 affects various Extended Life Cycle Support versions of Red Hat Enterprise Linux for IBM Power and IBM z Systems.
When was RHSA-2026:48866 published?
RHSA-2026:48866 was published on July 30, 2026.