Multiple Vulnerabilities in Fedora 44 Affecting Coreutils and ABRT

Multiple Vulnerabilities in Fedora 44 Affecting Coreutils and ABRT

First seen 5 Aug 2026, 08:01 UTC Linuxsecurityfedoraproject.org 79% similarity 70.5

Article Content

Browse articles
ThreatCluster

On August 3, 2026, Fedora released updates addressing critical vulnerabilities in two packages: ABRT and Coreutils. The ABRT tool had multiple issues, including content injection and race conditions, linked to CVEs 2026-54228, 2026-54229, 2026-54230, and 2026-54231, all published on June 13, 2026. These vulnerabilities could allow local attackers to exploit system resources and escalate privileges. Additionally, Coreutils was updated to fix a denial of service vulnerability (CVE-2026-56391) related to out-of-bounds reads, published on July 24, 2026. Users are advised to audit Linux privileges and apply the updates immediately to mitigate risks. The vulnerabilities could lead to significant system compromise if not addressed promptly.

Key Points: • Fedora 44 ABRT vulnerabilities allow local privilege escalation and content injection. • Coreutils has a denial of service vulnerability that can be exploited with multibyte input. • Immediate updates are recommended to mitigate risks associated with these vulnerabilities.

ThreatCluster AI How this analysis works

Timeline

2026-06-13
Multiple CVEs published for ABRT vulnerabilities
CVE-2026-54228, CVE-2026-54229, CVE-2026-54230, and CVE-2026-54231 disclosed, affecting ABRT functionality.
Linuxsecurity
2026-06-13
CVE-2026-54228 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-06-13
CVE-2026-54229 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-06-13
CVE-2026-54231 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-06-13
CVE-2026-54230 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-07-24
CVE-2026-56391 published for Coreutils
Denial of service vulnerability disclosed in GNU Coreutils affecting the uniq command.
Linuxsecurity
2026-08-03
Fedora updates released for ABRT and Coreutils
Updates addressing critical vulnerabilities in ABRT and Coreutils were released, urging users to apply them.
Linuxsecurity

Community

Browse all →

Tracked Entities in This Story