← All Advisories

CVE-2026-54230

Last refreshed2026-10-03

Status: UPDATED  |  Advisory ID: CVE-2026-54230

Key Details

CVECVE-2026-54230
CVSS Score / Version7.0 (High) / CVSS v3.1
Updated2026-09-21
CVSS VectorCVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS Proseattack vector is local; attack complexity is high; privileges required is low; user interaction is none; scope is unchanged; confidentiality impact is high; integrity impact is high; availability impact is high.
Affected productssee table below
Classified asCWE-59 (Improper Link Resolution Before File Access ('Link Following'))

Affected Products, Subsystems & Sectors

VendorProductAffected VersionsPatch Status
Red HatEnterprise Linux
Red HatRed Hat Enterprise Linux 8
Red HatRed Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support
Red HatRed Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On
Red HatRed Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support
Red HatRed Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On
Red HatRed Hat Enterprise Linux 8.8 Telecommunications Update Service
Red HatRed Hat Enterprise Linux 8.8 Update Services for SAP Solutions
Red HatRed Hat Enterprise Linux 7
Red HatRed Hat Enterprise Linux 7 Extended Lifecycle Support
SubsystemsEWS Workstation Delivery/Virtualization
SectorsAll Sectors

What to Know

A symlink following vulnerability was found in the ABRT post-create event handler scripts in libreport. Event scripts write output files using shell redirections without the O_NOFOLLOW flag. If the target file is replaced with a symlink, the shell process running as root follows the symlink and writes content to the symlink target, allowing arbitrary file overwrites on the system. (NVD)

What to Do

Monitor Red Hat's web page for any future patch releases. See vendor advisory link below.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-54230
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-54230
Vendor advisoryhttps://access.redhat.com/security/cve/CVE-2026-54230