Knox CVE Database
/
CVE-2015-5287
High
7.8

CVE-2015-5287: Red Hat Automatic Bug Reporting Tool Privilege Escalation Vulnerability

Red Hat Automatic Bug Reporting Tool (ABRT) contains a privilege escalation vulnerability that could allow local users with certain permissions to gain privileges via a symlink attack on a file with a predictable name. The impacted product(s) could be end-of-life (EoL) and/or end-of-service (EoS). Users are advised to discontinue use and/or transition to a supported version.

Added to the CISA KEV catalog:
August 26, 2026

Overview

The Automatic Bug Reporting Tool (ABRT) before version 2.7.1 contains a symlink-following flaw in its kernel coredump processor that allows a local attacker with write access to the ABRT dump directory to escalate privileges to root. By pre-placing a symlink at a predictable coredump path and triggering a crash of a process named starting with 'abrt', the attacker causes the hook to overwrite an arbitrary privileged file with coredump contents. Red Hat Enterprise Linux 6 and 7, Oracle Linux 7, and ABRT through version 2.7.0 are affected.

Vulnerability details

Affected vendor
Red Hat
Affected product
Automatic Bug Reporting Tool
Weakness type (CWE)
CWE-59

The flaw resides in abrt-hook-ccpp, the kernel-invoked coredump processor. When a process whose name begins with 'abrt' crashes, the hook constructs a predictable output path such as /var/spool/abrt/abrt-test-coredump and opens it using xopen3() without the O_NOFOLLOW flag. This omission means the open call will follow a symbolic link if one exists at that path. Because the hook runs as root and the path is predictable, an attacker who can write to the dump directory can pre-place a symlink before the crash occurs, redirecting the write to any file on the system.


An attacker with local access and write access to the ABRT dump directory places a symlink at the predictable coredump path pointing to a privileged target such as /proc/sys/kernel/modprobe. The attacker then executes a binary named starting with 'abrt' and sends it SIGSEGV. The hook, running as root, follows the symlink and writes the process's memory contents to the target file, effectively overwriting it with attacker-controlled data. This achieves arbitrary file write as root, enabling full privilege escalation. On default RHEL installations, write access to the dump directory requires abrt-user-level privileges as a precondition.

Severity and impact

7.8
High
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Attack vector
Local
Attack complexity
Low
Privileges required
Low
User interaction
None
Scope
Unchanged
Confidentiality impact
High
Integrity impact
High
Availability impact
High

Exploitation status

This vulnerability is confirmed as actively exploited in the wild — it is listed in CISA's Known Exploited Vulnerabilities (KEV) catalog.

Known ransomware campaign use
Unknown

Detection and monitoring

  • Monitor for unexpected symbolic links created under /var/spool/abrt/ or /var/tmp/abrt/ pointing outside those directories, particularly to paths such as /proc/sys/kernel/modprobe or other privileged system files.
  • Audit file-write events to /proc/sys/kernel/modprobe or other sensitive kernel tunables originating from abrt-hook-ccpp or the abrtd process, which should never write to those paths under normal operation.

Remediation

Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see References) guidance and CISA’s “Forensics Triage Requirements” (see References). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
Federal (FCEB) remediation due date
September 9, 2026

Additional hardening

  • Upgrade ABRT to version 2.7.1 or later on affected Red Hat Enterprise Linux 6 and 7 systems; the fix modifies xopen3() to include O_NOFOLLOW, preventing symlink traversal during coredump writes.
  • Restrict write permissions on /var/spool/abrt and /var/tmp/abrt so that only the abrt service account can create files or symlinks in those directories, reducing the attacker's ability to pre-place a malicious symlink.
  • Set 'PrivateReports = yes' in /etc/abrt/abrt.conf to prevent ABRT from chowning dump directories to the crashing process owner, limiting the conditions under which unprivileged users can influence dump directory contents.
  • Where ABRT is not operationally required, disable or remove the abrt and abrt-addon-ccpp packages to eliminate the attack surface entirely.

Key dates

Published (NVD)
December 7, 2015
Added to CISA KEV
August 26, 2026
Remediation deadline
September 9, 2026
Last updated
August 27, 2026

References

Frequently asked questions

Does CVE-2015-5287 affect my FedRAMP authorization?

If Red Hat Automatic Bug Reporting Tool runs inside your authorization boundary, yes, this affects your FedRAMP authorization. CVE-2015-5287 appears in CISA's Known Exploited Vulnerabilities (KEV) catalog, with a remediation deadline of September 9, 2026. An unpatched KEV inside your boundary is a finding your assessor and sponsoring agency will raise. You must either remediate it or formally document a mitigation before that review occurs. The deadline is not advisory.

How does Knox help me handle CVE-2015-5287?

Knox does not patch Red Hat Automatic Bug Reporting Tool on your behalf. Under the FedRAMP shared-responsibility model, remediating that software is your obligation. What Knox provides is the pre-authorized, single-tenant boundary in which you carry out that remediation, along with continuous compliance monitoring and audit-artifact coverage to document the fix for your next assessment. The work of applying the patch is yours. Managing your compliance posture while you do it is not something you handle alone.

How does Knox's monitoring help with vulnerabilities like this?

Knox's automated continuous monitoring platform watches your environment for newly disclosed vulnerabilities and compliance issues on an ongoing basis. That means exposure like CVE-2015-5287 surfaces during routine monitoring rather than only when an assessor flags it at review time, giving your team time to act before the finding becomes a formal problem.

How do I get FedRAMP authorized with Knox?

Knox runs a FedRAMP-as-a-Service platform. It gives SaaS vendors a pre-authorized cloud boundary on AWS, Azure, and GCP. Your application inherits 60-80% of the required security controls. You reach FedRAMP authorization in about 90 days for roughly 90% less than the traditional $3.5M path. Book a meeting and Knox will map your path to authorization.

What happens if CVE-2015-5287 isn't remediated by September 9, 2026?

If CVE-2015-5287 is not remediated by September 9, 2026, it becomes a Plan of Action and Milestones (POA&M) item. A growing POA&M list is what turns a routine continuous-monitoring review into a difficult conversation with your sponsoring agency. Meeting the deadline keeps your authorization in good standing and the agency relationship intact.

Ready to achieve FedRAMP authorization in 90 days or less?

Schedule a meeting to discuss scope, parse readiness, and map your company’s accelerated path to FedRAMP authorization.

Book a Meeting