216.73.216.226

CVE-2026-54231

· Published 13/06/2026 05:16 · Modified 13/06/2026 03:16 · Author: The MITRE Corporation

Labels: CVE-2026-54231 2026-06-13CVE-2026-54231CWE-74[email protected]

Essential information

Published
13/06/2026 05:16
Modified
13/06/2026 03:16
Author
The MITRE Corporation
Creator
The MITRE Corporation
CVSS
5.5 MEDIUM (v3.1)
CISA KEV
No
CWE
CWE-74
CVSS vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N

CVSS metrics

Description

A content injection vulnerability was found in the ABRT post-create event handler scripts in libreport. The event script queries the systemd journal for log entries matching the crashed process and writes the results to files in the dump directory without sanitizing embedded control characters. A local user can inject arbitrary content into the journal output by embedding newline characters in syslog messages, controlling the content that root writes to dump directory files.

NVD status

Status
Received — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
redhat / libreport cpe:2.3:a:redhat:libreport:*:*:*:*:*:*:*:*

References