Skip to content
Fedora 44 abrt Vulnerability in Content Injection and Race Condition

Fedora 44 abrt Vulnerability in Content Injection and Race Condition

Linuxsecurity LinuxSecurity Advisories August 5, 2026

Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges ×

abrt is a tool to help users to detect defects in applications and

to create a bug report with all information needed by maintainer to fix it.

It uses plugin system to extend its functionality.

Update to 2.17.9 Resolves: rhbz#2484614 Resolves: CVE-2026-54230 Resolves: CVE-2026-54231 Resolves: CVE-2026-54228 Resolves: CVE-2026-54229

* Mon Aug 3 2026 Michal Srb - 2.17.9-1 - Fix journal entry spoofing in journal dump services - Resolves: rhbz#2484614 - Fix symlink following in event handler scripts - Resolves: CVE-2026-54230 - Fix content injection in journal log collection - Resolves: CVE-2026-54231 - Fix TOCTOU in SetElement/DeleteElement - Resolves: CVE-2026-54228 - Fix race condition in ChownProblemDir - Resolves: CVE-2026-54229 * Wed Jul 22 2026 Python Maint - 2.17.8-6 - Rebuilt for Python 3.15.0b4 ABI change * Wed Jul 15 2026 Fedora Release Engineering - 2.17.8-5 - Rebuilt for * Thu Jun 4 2026 Python Maint - 2.17.8-4 - Rebuilt for Python 3.15

* Mon Aug 3 2026 Michal Srb - 2.17.9-1 - Fix journal entry spoofing in journal dump services - Resolves: rhbz#2484614 - Fix symlink following in event handler scripts - Resolves: CVE-2026-54230 - Fix content injection in journal log collection - Resolves: CVE-2026-54231 - Fix TOCTOU in SetElement/DeleteElement - Resolves: CVE-2026-54228 - Fix race condition in ChownProblemDir - Resolves: CVE-2026-54229 * Wed Jul 22 2026 Python Maint - 2.17.8-6 - Rebuilt for Python 3.15.0b4 ABI change * Wed Jul 15 2026 Fedora Release Engineering - 2.17.8-5 - Rebuilt for * Thu Jun 4 2026 Python Maint - 2.17.8-4 - Rebuilt for Python 3.15

[ 1 ] Bug #2484614 - ABRT abrt-dump-journal-core trusts spoofed systemd-coredump journal fields, allowing local root file disclosure [ 2 ] Bug #2488616 - CVE-2026-54228 abrt: TOCTOU race condition in abrt-dbus SetElement allows arbitrary file writes to dump directories [fedora-all] [ 3 ] Bug #2488617 - CVE-2026-54229 abrt: ChownProblemDir succeeds during active post-create event processing due to inadequate locking [fedora-all] [ 4 ] Bug #2488618 - CVE-2026-54231 abrt: unsanitized systemd journal content written to dump directory files enables content injection [fedora-all] [ 5 ] Bug #2488619 - CVE-2026-54230 abrt: event handler scripts follow symlinks when writing output files, allowing arbitrary file overwrites [fedora-all] ...

This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-a7417466a1' at the command line. For more information, refer to the dnf documentation available at

Get the latest Linux and open source security news straight to your inbox.