Abrt Project maintains a focused system crash-reporting utility for Linux that facilitates automated collection and analysis of application and kernel failures, with its vulnerability footprint centered on the core abrt product. The durable signal reflects the tool's privileged access to process state and crash data, with observed weaknesses clustering around race conditions in concurrent resource handling and improper access controls around sensitive diagnostic information. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Abrt Project over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-54230HIGH A symlink following vulnerability was found in the ABRT post-create event handler scripts in libreport. Event scripts write output files using shell redirections without the O_NOFO | Jun 13, 2026 | 7.8 | 34 | NO | NO |
CVE-2015-1862HIGH The crash reporting feature in Abrt allows local users to gain privileges by leveraging an execve by root after a chroot into a user-specified directory in a namedspaced environmen | Feb 9, 2018 | 7.0 | 31 | NO | YES |
CVE-2026-54231MEDIUM A content injection vulnerability was found in the ABRT post-create event handler scripts in libreport. The event script queries the systemd journal for log entries matching the cr | Jun 13, 2026 | 5.5 | 26 | NO | NO |
CVE-2011-4088HIGH ABRT might allow attackers to obtain sensitive information from crash reports. | Jan 31, 2020 | 7.5 | 25 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Abrt Project.
Media articles that mention a CVE ID that affects a product developed by Abrt Project — matched by CVE ID, not by vendor name.