Red Hat ABRT Privilege Escalation Vulnerability: Early Warning
- Severity
- HIGH
- Affected component
- abrt (other)
- Patched version
- Not yet available
An early warning has been issued for a privilege escalation vulnerability in the Red Hat Automatic Bug Reporting Tool (ABRT). Local users with certain permissions may be able to gain elevated privileges.
What happened
The Red Hat Automatic Bug Reporting Tool (ABRT) reportedly contains a privilege escalation vulnerability that could allow local users with certain permissions to gain elevated privileges via a symlink attack on a file with a predictable name. This vulnerability, tracked as CVE-2015-5287, is under investigation and has been flagged as exploited in the wild. To assess your exposure, review your use of ABRT and identify any local users with permissions that could be leveraged in a symlink attack.
The vulnerability was first flagged on 2026-08-26T00:00:00+00:00 and is listed in the CISA Known Exploited Vulnerabilities Catalog. The severity of this threat is high, and it is recommended to discontinue use of ABRT and transition to a supported version.
What to do about it
- Discontinue use of the Red Hat Automatic Bug Reporting Tool (ABRT) immediately.
- Transition to a supported version of ABRT if available.
- Review your system for any local users with permissions that could be exploited in a symlink attack.
- Monitor the primary sources for updates on this vulnerability and any official fixes that may be published.
- Consider implementing additional security measures to mitigate the risk of privilege escalation attacks.
How 0Day would have caught this
abrt is anywhere in your dependency tree, the engineers who own the affected repositories get a push alert the moment it is flagged — no manual audit to remember to run.Read how this differs from waiting on a scanner to catch a known advisory, or see the exact, read-only access 0Day needs to do this for an organization.
Frequently asked questions
Am I affected?
You may be affected if you are using the Red Hat Automatic Bug Reporting Tool (ABRT) and have local users with certain permissions.
What should I do right now?
Discontinue use of ABRT and transition to a supported version if available. Monitor primary sources for updates.
Has this been exploited in the wild?
Yes, this vulnerability is reportedly being exploited in the wild.