Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

rocky логотип

RLSA-2025:22760

Опубликовано: 21 мая 2026
Источник: rocky
Оценка: Important

Описание

Important: abrt security update

The Automatic Bug Reporting Tool (ABRT) recognizes defects in applications and creates bug reports that help maintainers fix the defects. ABRT uses a plug-in system to extend its functionality.

Security Fix(es):

  • abrt: Command-injection in ABRT leading to local privilege escalation (CVE-2025-12744)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Затронутые продукты

  • Rocky Linux 8

НаименованиеАрхитектураРелизRPM
abrtx86_6425.el8_10.rocky.0.1abrt-2.10.9-25.el8_10.rocky.0.1.x86_64.rpm
abrt-addon-ccppx86_6425.el8_10.rocky.0.1abrt-addon-ccpp-2.10.9-25.el8_10.rocky.0.1.x86_64.rpm
abrt-addon-coredump-helperx86_6425.el8_10.rocky.0.1abrt-addon-coredump-helper-2.10.9-25.el8_10.rocky.0.1.x86_64.rpm
abrt-addon-kerneloopsx86_6425.el8_10.rocky.0.1abrt-addon-kerneloops-2.10.9-25.el8_10.rocky.0.1.x86_64.rpm
abrt-addon-pstoreoopsx86_6425.el8_10.rocky.0.1abrt-addon-pstoreoops-2.10.9-25.el8_10.rocky.0.1.x86_64.rpm
abrt-addon-vmcorex86_6425.el8_10.rocky.0.1abrt-addon-vmcore-2.10.9-25.el8_10.rocky.0.1.x86_64.rpm
abrt-addon-xorgx86_6425.el8_10.rocky.0.1abrt-addon-xorg-2.10.9-25.el8_10.rocky.0.1.x86_64.rpm
abrt-clix86_6425.el8_10.rocky.0.1abrt-cli-2.10.9-25.el8_10.rocky.0.1.x86_64.rpm
abrt-cli-ngx86_6425.el8_10.rocky.0.1abrt-cli-ng-2.10.9-25.el8_10.rocky.0.1.x86_64.rpm
abrt-console-notificationx86_6425.el8_10.rocky.0.1abrt-console-notification-2.10.9-25.el8_10.rocky.0.1.x86_64.rpm

Показывать по

Связанные CVE

Исправления

Связанные уязвимости

CVSS3: 8.8
redhat
8 месяцев назад

A flaw was found in the ABRT daemon’s handling of user-supplied mount information.ABRT copies up to 12 characters from an untrusted input and places them directly into a shell command (docker inspect %s) without proper validation. An unprivileged local user can craft a payload that injects shell metacharacters, causing the root-running ABRT process to execute attacker-controlled commands and ultimately gain full root privileges.

CVSS3: 8.8
nvd
8 месяцев назад

A flaw was found in the ABRT daemon’s handling of user-supplied mount information.ABRT copies up to 12 characters from an untrusted input and places them directly into a shell command (docker inspect %s) without proper validation. An unprivileged local user can craft a payload that injects shell metacharacters, causing the root-running ABRT process to execute attacker-controlled commands and ultimately gain full root privileges.

CVSS3: 8.8
github
8 месяцев назад

A flaw was found in the ABRT daemon’s handling of user-supplied mount information.ABRT copies up to 12 characters from an untrusted input and places them directly into a shell command (docker inspect %s) without proper validation. An unprivileged local user can craft a payload that injects shell metacharacters, causing the root-running ABRT process to execute attacker-controlled commands and ultimately gain full root privileges.

oracle-oval
8 месяцев назад

ELSA-2025-22760: abrt security update (IMPORTANT)