CISA added CVE-2015-5287, a local privilege escalation flaw in Red Hat's Automatic Bug Reporting Tool, to the Known Exploited Vulnerabilities catalog on 2026-08-26 with a remediation deadline of 2026-09-09.
What Is It
The abrt-hook-ccpp help program in Automatic Bug Reporting Tool (ABRT) before version 2.7.1 allows local users with certain permissions to gain privileges via a symlink attack on a file with a predictable name. NVD cites /var/tmp/abrt/abrt-hax-coredump and /var/spool/abrt/abrt-hax-coredump as demonstrated targets. The weakness is classified as CWE-59 (link following).
NVD scores it CVSS 3.1 base 7.8 (HIGH), vector AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H, local attack vector, low complexity, low privileges required, no user interaction, and high confidentiality, integrity, and availability impact.
Why It Matters
CISA's KEV listing confirms active exploitation. The SSVC assessment recorded by CISA marks exploitation as active, automatable as no, and technical impact as total. Public exploit material exists and is referenced by NVD, including an Exploit-DB entry and an oss-security posting.
CISA further notes the affected product may be end-of-life or end-of-service, and advises users to discontinue use and/or transition to a supported version.
What's Vulnerable
Per NVD's CPE configuration:
- Red Hat Automatic Bug Reporting Tool, versions up to and including 2.7.0
- Red Hat Enterprise Linux 6.0 and 7.0
- Red Hat Enterprise Linux Desktop, HPC Node, Server, and Workstation 7.0
- Oracle Linux 7
Patch Status
Fixed in ABRT 2.7.1. The upstream fix is commit 3c1b60cfa62d39e5fff5a53a5bc53dae189e740e in the abrt repository, and Red Hat published errata RHSA-2015-2505.
CISA's required action: apply mitigations per vendor instructions in accordance with BOD 26-04 (Prioritizing Security Updates Based on Risk) and CISA's Forensics Triage Requirements; follow applicable BOD 26-04 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure. Known ransomware campaign use is listed as Unknown.
Sources
- CISA KEV Catalog; CVE-2015-5287 entry (added 2026-08-26, due 2026-09-09)
- NVD, https://nvd.nist.gov/vuln/detail/CVE-2015-5287
- Upstream patch commit; https://github.com/abrt/abrt/commit/3c1b60cfa62d39e5fff5a53a5bc53dae189e740e
- Red Hat errata RHSA-2015-2505; http://rhn.redhat.com/errata/RHSA-2015-2505.html
- Red Hat Bugzilla #1266837; https://bugzilla.redhat.com/show_bug.cgi?id=1266837
- oss-security mailing list; http://www.openwall.com/lists/oss-security/2015/12/01/1
- Exploit-DB 38832; https://www.exploit-db.com/exploits/38832/
- Packet Storm; http://packetstormsecurity.com/files/154592/ABRT-sosreport-Privilege-Escalation.html
- Oracle Linux Bulletin; http://www.oracle.com/technetwork/topics/security/linuxbulletinoct2015-2719645.html
- CISA BOD 26-04; https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk