THREATOPS
THREAT OPSThreat News › [NVD] CVE-2026-54228 (HIGH 7.8) — A time-of-check time-of-use (TOCTOU) race condition was found in the abrt-dbus D-Bus service's SetElement method. Between dump directory creation and post-create event execution, any local user can call SetElement to write arbitrary text files into the root-owned dump directory,

[NVD] CVE-2026-54228 (HIGH 7.8) — A time-of-check time-of-use (TOCTOU) race condition was found in the abrt-dbus D-Bus service's SetElement method. Between dump directory creation and post-create event execution, any local user can call SetElement to write arbitrary text files into the root-owned dump directory,

lownvdPublished 2026-06-13

CVE-2026-54228 CVSS: 7.8 HIGH Published: 2026-06-13T03:16:21.440

A time-of-check time-of-use (TOCTOU) race condition was found in the abrt-dbus D-Bus service's SetElement method. Between dump directory creation and post-create event execution, any local user can call SetElement to write arbitrary text files into the root-owned dump directory, bypassing package validation and allowing crashes of u

Indicators of compromise

Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-54228