Red Hat Updates Deprecated ABRT on RHEL 8 Extended Support

P1 — VALIDATE AND UPDATEHigh / Medium · 7.0 / 5.5 (CVSS v3.1)EXPLOITATION: NOT STATED

Quick Answer

Red Hat published RHSA-2026:69115 and RHSA-2026:69117 for two ABRT vulnerabilities across RHEL 8.6 and 8.8 extended-support streams. CVE-2026-54230 is a 7.0 High symlink-based file-overwrite flaw; CVE-2026-54231 is a 5.5 Medium journal-content injection flaw. Red Hat provides branch-specific fixed builds.

Update Or Disable Deprecated ABRT Deployments

What to do now: Identify entitled RHEL 8.6 and 8.8 systems with ABRT packages or services, install the branch-specific Red Hat build, or follow Red Hat's supported disable or removal guidance where ABRT is unnecessary, then validate crash reporting and logging.

Open the authoritative advisory

Last verified: 2026-09-21 UTC. Recheck the current authoritative advisory and entitled repository before changing production.

Scope And Authority

Product scopeRHEL 8.6 AUS/EUS Extension and RHEL 8.8 SAP/TUS ABRT
AdvisoryRHSA-2026:69115 / RHSA-2026:69117
CVEsCVE-2026-54230, CVE-2026-54231
Authoritative release dateRHSA-2026:69115 at 2026-09-21 04:04:51 UTC; RHSA-2026:69117 at 04:07:21 UTC
Authority revision date2026-09-21 04:07:54 UTC and 04:07:55 UTC, respectively
Affected versionsEntitled RHEL 8.6 AUS/EUS Extension and RHEL 8.8 E4S/TUS ABRT streams before the advisory-listed builds
Fixed versionabrt 2.10.9-25.el8_6.2 (RHEL 8.6) / 2.10.9-25.el8_8.2 (RHEL 8.8)
CVSS base score7.0 / 5.5 (CVSS v3.1)
CVSS severityHigh / Medium
Exploitation statusNot stated by Red Hat; no exploitation claim is inferred.

What Changed

The updates prevent a local symlink condition from overwriting files and sanitize journal content used in ABRT processing. Red Hat maps the same CVEs to branch-specific RHEL 8.6 and 8.8 packages; the advisories do not establish compromise or apply where ABRT is absent.

What To Validate Now

  1. Inventory. Locate RHEL 8.6 AUS/EUS Extension and RHEL 8.8 SAP E4S or Telecommunications Update Service systems with ABRT packages, active services, local user access, automated crash processing, and integrations that consume ABRT output.
  2. Establish applicability. Match the exact entitled branch and NVR; determine whether local users or processes can create the stated symlink or journal-content conditions.
  3. Remediate. Update to 2.10.9-25.el8_6.2 on RHEL 8.6 or 2.10.9-25.el8_8.2 on RHEL 8.8, or a supported superseding build. Where ABRT is unnecessary, follow Red Hat guidance to disable or remove the deprecated component.
  4. Validate. Confirm package NVRs and service state, test required crash-reporting and journal workflows, review relevant local activity, and document any retained exception.
  5. Retain evidence. Preserve asset and owner identifiers, the applicability decision, before-and-after versions, change approval, installation output, validation results, and any exception or rollback record.

Operational Cautions

Disabling or removing crash-reporting components can affect support and diagnostic workflows. Coordinate with operations and application owners, preserve required diagnostic evidence, and do not treat local access or severity as proof of exploitation.

Evidence To Retain

  • Exact product, release stream, package or application version, enabled feature, environment, and accountable owner.
  • UTC timestamps, source advisory revision, approved change record, installer or package-manager output, and resulting version.
  • Relevant logs and monitoring evidence, test results, exceptions, compensating controls, and rollback decisions.

Related TechGeeks Resources

Authoritative References

Correction policy: If the authority changes affected versions, fixed versions, severity, exploitation information, mitigations, or required action, TechGeeks will update this notice and its verification date.