CVE-2026-54230: Fedoraproject Fedora

High severity, CVSS 7.8. EPSS: 0.2% chance of exploitation in the next 30 days.

A symlink following vulnerability was found in the ABRT post-create event handler scripts in libreport. Event scripts write output files using shell redirections without the O_NOFOLLOW flag. If the target file is replaced with a symlink, the shell process running as root follows the symlink and writes content to the symlink target, allowing arbitrary file overwrites on the system.

Affected products

  • Fedoraproject Fedora: version 43 only; version 44 only
  • Red Hat Automatic Bug Reporting Tool: any version
  • Red Hat Enterprise Linux: version 7.0 only; version 8.0 only

Published 2026-06-13. Last modified 2026-09-21.