Red Hat Automatic Bug Reporting Tool (ABRT) contains a privilege escalation vulnerability that could allow local users with certain permissions to gain privileges via a symlink attack on a file with a predictable name. The impacted product(s) could be end-of-life (EoL) and/or end-of-service (EoS). Users are advised to discontinue use and/or transition to a supported version.
The Automatic Bug Reporting Tool (ABRT) before version 2.7.1 contains a symlink-following flaw in its kernel coredump processor that allows a local attacker with write access to the ABRT dump directory to escalate privileges to root. By pre-placing a symlink at a predictable coredump path and triggering a crash of a process named starting with 'abrt', the attacker causes the hook to overwrite an arbitrary privileged file with coredump contents. Red Hat Enterprise Linux 6 and 7, Oracle Linux 7, and ABRT through version 2.7.0 are affected.
The flaw resides in abrt-hook-ccpp, the kernel-invoked coredump processor. When a process whose name begins with 'abrt' crashes, the hook constructs a predictable output path such as /var/spool/abrt/abrt-test-coredump and opens it using xopen3() without the O_NOFOLLOW flag. This omission means the open call will follow a symbolic link if one exists at that path. Because the hook runs as root and the path is predictable, an attacker who can write to the dump directory can pre-place a symlink before the crash occurs, redirecting the write to any file on the system.
An attacker with local access and write access to the ABRT dump directory places a symlink at the predictable coredump path pointing to a privileged target such as /proc/sys/kernel/modprobe. The attacker then executes a binary named starting with 'abrt' and sends it SIGSEGV. The hook, running as root, follows the symlink and writes the process's memory contents to the target file, effectively overwriting it with attacker-controlled data. This achieves arbitrary file write as root, enabling full privilege escalation. On default RHEL installations, write access to the dump directory requires abrt-user-level privileges as a precondition.
This vulnerability is confirmed as actively exploited in the wild — it is listed in CISA's Known Exploited Vulnerabilities (KEV) catalog.
If Red Hat Automatic Bug Reporting Tool runs inside your authorization boundary, yes, this affects your FedRAMP authorization. CVE-2015-5287 appears in CISA's Known Exploited Vulnerabilities (KEV) catalog, with a remediation deadline of September 9, 2026. An unpatched KEV inside your boundary is a finding your assessor and sponsoring agency will raise. You must either remediate it or formally document a mitigation before that review occurs. The deadline is not advisory.
Knox does not patch Red Hat Automatic Bug Reporting Tool on your behalf. Under the FedRAMP shared-responsibility model, remediating that software is your obligation. What Knox provides is the pre-authorized, single-tenant boundary in which you carry out that remediation, along with continuous compliance monitoring and audit-artifact coverage to document the fix for your next assessment. The work of applying the patch is yours. Managing your compliance posture while you do it is not something you handle alone.
Knox's automated continuous monitoring platform watches your environment for newly disclosed vulnerabilities and compliance issues on an ongoing basis. That means exposure like CVE-2015-5287 surfaces during routine monitoring rather than only when an assessor flags it at review time, giving your team time to act before the finding becomes a formal problem.
Knox runs a FedRAMP-as-a-Service platform. It gives SaaS vendors a pre-authorized cloud boundary on AWS, Azure, and GCP. Your application inherits 60-80% of the required security controls. You reach FedRAMP authorization in about 90 days for roughly 90% less than the traditional $3.5M path. Book a meeting and Knox will map your path to authorization.
If CVE-2015-5287 is not remediated by September 9, 2026, it becomes a Plan of Action and Milestones (POA&M) item. A growing POA&M list is what turns a routine continuous-monitoring review into a difficult conversation with your sponsoring agency. Meeting the deadline keeps your authorization in good standing and the agency relationship intact.
Schedule a meeting to discuss scope, parse readiness, and map your company’s accelerated path to FedRAMP authorization.











_Horizontal_RGB.png)









