<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 12:04:12 +0000</lastBuildDate>
    <item>
      <title>ALSA-2026:54272 — Important: abrt security update</title>
      <link>https://cve.radiocsirt.org/vuln/alsa-2026:54272</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:8: abrt, AlmaLinux:8: abrt-addon-ccpp, AlmaLinux:8: abrt-addon-coredump-helper, AlmaLinux:8: abrt-addon-kerneloops, AlmaLinux:8: abrt-addon-pstoreoops, AlmaLinux:8: abrt-addon-vmcore, AlmaLinux:8: abrt-addon-xorg, AlmaLinux:8: abrt-cli, AlmaLinux:8: abrt-cli-ng, AlmaLinux:8: abrt-console-notification and 12 more&lt;/p&gt;
&lt;p&gt;The Automatic Bug Reporting Tool (ABRT) recognizes defects in applications and creates bug reports that help maintainers fix the defects. ABRT uses a plug-in system to extend its functionality.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* abrt: TOCTOU race condition in abrt-dbus SetElement allows arbitrary file writes to dump directories (CVE-2026-54228)
  * abrt: ChownProblemDir succeeds during active post-create event processing due to inadequate locking (CVE-2026-54229)
  * abrt: event handler scripts follow symlinks when writing output files, allowing arbitrary file overwrites (CVE-2026-54230)
  * abrt: unsanitized systemd journal content written to dump directory files enables content injection (CVE-2026-54231)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:8: abrt, AlmaLinux:8: abrt-addon-ccpp, AlmaLinux:8: abrt-addon-coredump-helper, AlmaLinux:8: abrt-addon-kerneloops, AlmaLinux:8: abrt-addon-pstoreoops, AlmaLinux:8: abrt-addon-vmcore, AlmaLinux:8: abrt-addon-xorg, AlmaLinux:8: abrt-cli, AlmaLinux:8: abrt-cli-ng, AlmaLinux:8: abrt-console-notification and 12 more&lt;/p&gt;
&lt;p&gt;The Automatic Bug Reporting Tool (ABRT) recognizes defects in applications and creates bug reports that help maintainers fix the defects. ABRT uses a plug-in system to extend its functionality.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* abrt: TOCTOU race condition in abrt-dbus SetElement allows arbitrary file writes to dump directories (CVE-2026-54228)
  * abrt: ChownProblemDir succeeds during active post-create event processing due to inadequate locking (CVE-2026-54229)
  * abrt: event handler scripts follow symlinks when writing output files, allowing arbitrary file overwrites (CVE-2026-54230)
  * abrt: unsanitized systemd journal content written to dump directory files enables content injection (CVE-2026-54231)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/alsa-2026:54272</guid>
    </item>
    <item>
      <title>EUVD-2026-372742</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-372742</link>
      <description>EUVD-2026-372742</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-372742</guid>
    </item>
    <item>
      <title>fkie_cve-2026-54231</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-54231</link>
      <description>&lt;p&gt;A content injection vulnerability was found in the ABRT post-create event handler scripts in libreport. The event script queries the systemd journal for log entries matching the crashed process and writes the results to files in the dump directory without sanitizing embedded control characters. A local user can inject arbitrary content into the journal output by embedding newline characters in syslog messages, controlling the content that root writes to dump directory files.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A content injection vulnerability was found in the ABRT post-create event handler scripts in libreport. The event script queries the systemd journal for log entries matching the crashed process and writes the results to files in the dump directory without sanitizing embedded control characters. A local user can inject arbitrary content into the journal output by embedding newline characters in syslog messages, controlling the content that root writes to dump directory files.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-54231</guid>
    </item>
    <item>
      <title>GHSA-p464-2mqm-5h37</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-p464-2mqm-5h37</link>
      <description>&lt;p&gt;A content injection vulnerability was found in the ABRT post-create event handler scripts in libreport. The event script queries the systemd journal for log entries matching the crashed process and writes the results to files in the dump directory without sanitizing embedded control characters. A local user can inject arbitrary content into the journal output by embedding newline characters in syslog messages, controlling the content that root writes to dump directory files.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A content injection vulnerability was found in the ABRT post-create event handler scripts in libreport. The event script queries the systemd journal for log entries matching the crashed process and writes the results to files in the dump directory without sanitizing embedded control characters. A local user can inject arbitrary content into the journal output by embedding newline characters in syslog messages, controlling the content that root writes to dump directory files.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-p464-2mqm-5h37</guid>
    </item>
    <item>
      <title>RHSA-2026:54272 — Red Hat Security Advisory: abrt security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2026:54272</link>
      <description>&lt;p&gt;abrt: TOCTOU race condition in abrt-dbus SetElement allows arbitrary file writes to dump directories abrt: ChownProblemDir succeeds during active post-create event processing due to inadequate locking abrt: event handler scripts follow symlinks when writing output files, allowing arbitrary file overwrites abrt: unsanitized systemd journal content written to dump directory files enables content injection&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;abrt: TOCTOU race condition in abrt-dbus SetElement allows arbitrary file writes to dump directories abrt: ChownProblemDir succeeds during active post-create event processing due to inadequate locking abrt: event handler scripts follow symlinks when writing output files, allowing arbitrary file overwrites abrt: unsanitized systemd journal content written to dump directory files enables content injection&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2026:54272</guid>
    </item>
    <item>
      <title>RHSA-2026:69115 — Red Hat Security Advisory: abrt security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2026:69115</link>
      <description>&lt;p&gt;abrt: event handler scripts follow symlinks when writing output files, allowing arbitrary file overwrites abrt: unsanitized systemd journal content written to dump directory files enables content injection&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;abrt: event handler scripts follow symlinks when writing output files, allowing arbitrary file overwrites abrt: unsanitized systemd journal content written to dump directory files enables content injection&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2026:69115</guid>
    </item>
    <item>
      <title>RLSA-2026:54272 — Important: abrt security update</title>
      <link>https://cve.radiocsirt.org/vuln/rlsa-2026:54272</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Rocky Linux:8: abrt&lt;/p&gt;
&lt;p&gt;The Automatic Bug Reporting Tool (ABRT) recognizes defects in applications and creates bug reports that help maintainers fix the defects. ABRT uses a plug-in system to extend its functionality.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* abrt: TOCTOU race condition in abrt-dbus SetElement allows arbitrary file writes to dump directories (CVE-2026-54228)&lt;/p&gt;
&lt;p&gt;* abrt: ChownProblemDir succeeds during active post-create event processing due to inadequate locking (CVE-2026-54229)&lt;/p&gt;
&lt;p&gt;* abrt: event handler scripts follow symlinks when writing output files, allowing arbitrary file overwrites (CVE-2026-54230)&lt;/p&gt;
&lt;p&gt;* abrt: unsanitized systemd journal content written to dump directory files enables content injection (CVE-2026-54231)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Rocky Linux:8: abrt&lt;/p&gt;
&lt;p&gt;The Automatic Bug Reporting Tool (ABRT) recognizes defects in applications and creates bug reports that help maintainers fix the defects. ABRT uses a plug-in system to extend its functionality.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* abrt: TOCTOU race condition in abrt-dbus SetElement allows arbitrary file writes to dump directories (CVE-2026-54228)&lt;/p&gt;
&lt;p&gt;* abrt: ChownProblemDir succeeds during active post-create event processing due to inadequate locking (CVE-2026-54229)&lt;/p&gt;
&lt;p&gt;* abrt: event handler scripts follow symlinks when writing output files, allowing arbitrary file overwrites (CVE-2026-54230)&lt;/p&gt;
&lt;p&gt;* abrt: unsanitized systemd journal content written to dump directory files enables content injection (CVE-2026-54231)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rlsa-2026:54272</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-3470 — Red Hat Enterprise Linux (abrt): Mehrere Schwachstellen ermöglichen Manipulation von Dateien</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-3470</link>
      <description>&lt;p&gt;Ein lokaler Angreifer kann mehrere Schwachstellen in Red Hat Enterprise Linux ausnutzen, um Dateien zu manipulieren.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein lokaler Angreifer kann mehrere Schwachstellen in Red Hat Enterprise Linux ausnutzen, um Dateien zu manipulieren.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-3470</guid>
    </item>
  </channel>
</rss>
