Back

HIGH

abrt: local privilege escalation through kernel.core_pattern

Published Feb 9, 2018

Description

The crash reporting feature in Abrt allows local users to gain privileges by leveraging an execve by root after a chroot into a user-specified directory in a namedspaced environment.

Affected products

Remediation

Red Hat statement

Not vulnerable. This issue does not affect the version of abrt package as shipped with Red Hat Enterprise Linux 6 and 7. Additional information about this is available at https://bugzilla.redhat.com/show_bug.cgi?id=1211223#c7

Metrics

Weaknesses (1)

References (13)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Feb 9, 2018
Updated Aug 6, 2024
Reserved Feb 17, 2015
NVD
Status Modified
Modified Aug 26, 2026
Red Hat
Severity Important
Public date Apr 14, 2015