DIRAS TAKE
Urgent: CISA placed this issue on the KEV catalog with a mandated remediation schedule and working exploit code is public, so prioritize mitigation for exposed ABRT installs immediately.
What is CVE-2015-5287?
A local account that can write to ABRT’s temporary or spool locations can exploit a symlink weakness in the abrt-hook-ccpp helper to elevate privileges on systems running Automatic Bug Reporting Tool; this is tracked as CVE-2015-5287. The issue affects ABRT releases prior to 2.7.1 and requires only local file creation or manipulation in the predictable paths the helper uses, not remote network access or interactive user deception. The weakness is classified as CWE-59 (Link Following).
Vector CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Which versions of Red Hat Automatic Bug Reporting Tool are affected?
| BRANCH | AFFECTED | FIXED |
|---|
Is CVE-2015-5287 being exploited?
CISA added CVE-2015-5287 to the Known Exploited Vulnerabilities catalog on 2026-08-26, and US federal agencies were required to remediate by 2026-09-09; public exploit code for this vulnerability is available.
How to fix CVE-2015-5287
- Implement Red Hat’s guidance and any recommended mitigations for ABRT without delay.
- Prevent local accounts from creating or modifying files in ABRT’s predictable temporary and spool directories.
- Remove or limit unnecessary local privileges and accounts that can reach ABRT helper files.
- Isolate or discontinue ABRT on internet-facing or multi-tenant hosts until a vendor fix is applied and monitor logs for signs of exploitation.
Frequently asked questions
Is CVE-2015-5287 being actively exploited?
CISA added CVE-2015-5287 to the Known Exploited Vulnerabilities catalog on 2026-08-26 with a remediation due date of 2026-09-09, and public exploit code for the flaw is available.
Which Automatic Bug Reporting Tool versions are affected by CVE-2015-5287?
ABRT versions before 2.7.1 are reported as affected by CVE-2015-5287.
Is there a patch for CVE-2015-5287?
No vendor patch is listed in the provided facts; follow Red Hat guidance for mitigations or discontinue use if updates are unavailable.
Does CVE-2015-5287 require authentication?
The flaw requires a local user with the ability to create or alter files in ABRT’s predictable directories rather than remote authentication.
References
- nvd.nist.gov/vuln/detail/CVE-2015-5287
- cve.org/CVERecord?id=CVE-2015-5287
- cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2015-5287
- rhn.redhat.com/errata/RHSA-2015-2505.html
- exploit-db.com/exploits/38832
- openwall.com/lists/oss-security/2015/12/01/1
- oracle.com/technetwork/topics/security/linuxbulletinoct2015-2719645.html
- bugzilla.redhat.com/show_bug.cgi?id=1266837
- securityfocus.com/bid/78137
- github.com/abrt/abrt/commit/3c1b60cfa62d39e5fff5a53a5bc53dae189e740e
- packetstormsecurity.com/files/154592/ABRT-sosreport-Privilege-Escalation.html
- All Red Hat CVEs on CVE Radar
- CVEs published in September 2026