<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Cpe:2.3:o:oracle:linux:7:*:*:*:*:*:*:* - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/cpes/cpe2.3ooraclelinux7/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Wed, 26 Aug 2026 20:17:10 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/cpes/cpe2.3ooraclelinux7/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Local Privilege Escalation in Red Hat Automatic Bug Reporting Tool</title><link>https://feed.craftedsignal.io/briefs/2026-08-abrt-priv-esc/</link><pubDate>Wed, 26 Aug 2026 20:17:10 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-08-abrt-priv-esc/</guid><description>The Red Hat Automatic Bug Reporting Tool (ABRT) contains a local privilege escalation vulnerability (CVE-2015-5287) that allows unauthorized users to gain elevated access via symlink attacks.</description><content:encoded><![CDATA[<p>CVE-2015-5287 is a privilege escalation vulnerability within the Red Hat Automatic Bug Reporting Tool (ABRT), an open-source utility designed to collect and report diagnostic data. An attacker with local access can exploit improper file handling during the reporting process, specifically through a symlink attack targeting files with predictable names. By redirecting file operations to sensitive system files, a malicious local user may gain escalated privileges on the host system. This vulnerability has been added to the CISA Known Exploited Vulnerabilities (KEV) catalog. Given that ABRT is frequently installed on RHEL-based systems, security teams should assess current exposure, particularly on systems running older or end-of-life software versions, as indicated by CISA BOD 26-04.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation allows a local user to escalate privileges beyond their current authorization level, potentially leading to full system compromise. The impact is primarily restricted to systems where the ABRT service is active and local users have sufficient permissions to initiate reporting processes. Organizations still running affected, legacy versions of RHEL or related distributions are at the highest risk.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Transition away from end-of-life versions of the Red Hat Automatic Bug Reporting Tool as advised by the vendor and CISA.</li>
<li>Evaluate internet-facing assets for the presence of the vulnerable ABRT package and ensure patching or removal in accordance with CISA BOD 26-04.</li>
<li>Conduct a forensics triage of assets identified as running legacy or vulnerable versions of ABRT following CISA guidance.</li>
</ul>
]]></content:encoded><category domain="severity">medium</category><category domain="type">advisory</category></item></channel></rss>