Red Hat Updates Deprecated ABRT on RHEL 8 Extended Support
Quick Answer
Red Hat published RHSA-2026:69115 and RHSA-2026:69117 for two ABRT vulnerabilities across RHEL 8.6 and 8.8 extended-support streams. CVE-2026-54230 is a 7.0 High symlink-based file-overwrite flaw; CVE-2026-54231 is a 5.5 Medium journal-content injection flaw. Red Hat provides branch-specific fixed builds.
Update Or Disable Deprecated ABRT Deployments
What to do now: Identify entitled RHEL 8.6 and 8.8 systems with ABRT packages or services, install the branch-specific Red Hat build, or follow Red Hat's supported disable or removal guidance where ABRT is unnecessary, then validate crash reporting and logging.
Last verified: 2026-09-21 UTC. Recheck the current authoritative advisory and entitled repository before changing production.
Scope And Authority
| Product scope | RHEL 8.6 AUS/EUS Extension and RHEL 8.8 SAP/TUS ABRT |
|---|---|
| Advisory | RHSA-2026:69115 / RHSA-2026:69117 |
| CVEs | CVE-2026-54230, CVE-2026-54231 |
| Authoritative release date | RHSA-2026:69115 at 2026-09-21 04:04:51 UTC; RHSA-2026:69117 at 04:07:21 UTC |
| Authority revision date | 2026-09-21 04:07:54 UTC and 04:07:55 UTC, respectively |
| Affected versions | Entitled RHEL 8.6 AUS/EUS Extension and RHEL 8.8 E4S/TUS ABRT streams before the advisory-listed builds |
| Fixed version | abrt 2.10.9-25.el8_6.2 (RHEL 8.6) / 2.10.9-25.el8_8.2 (RHEL 8.8) |
| CVSS base score | 7.0 / 5.5 (CVSS v3.1) |
| CVSS severity | High / Medium |
| Exploitation status | Not stated by Red Hat; no exploitation claim is inferred. |
What Changed
The updates prevent a local symlink condition from overwriting files and sanitize journal content used in ABRT processing. Red Hat maps the same CVEs to branch-specific RHEL 8.6 and 8.8 packages; the advisories do not establish compromise or apply where ABRT is absent.
What To Validate Now
- Inventory. Locate RHEL 8.6 AUS/EUS Extension and RHEL 8.8 SAP E4S or Telecommunications Update Service systems with ABRT packages, active services, local user access, automated crash processing, and integrations that consume ABRT output.
- Establish applicability. Match the exact entitled branch and NVR; determine whether local users or processes can create the stated symlink or journal-content conditions.
- Remediate. Update to 2.10.9-25.el8_6.2 on RHEL 8.6 or 2.10.9-25.el8_8.2 on RHEL 8.8, or a supported superseding build. Where ABRT is unnecessary, follow Red Hat guidance to disable or remove the deprecated component.
- Validate. Confirm package NVRs and service state, test required crash-reporting and journal workflows, review relevant local activity, and document any retained exception.
- Retain evidence. Preserve asset and owner identifiers, the applicability decision, before-and-after versions, change approval, installation output, validation results, and any exception or rollback record.
Operational Cautions
Disabling or removing crash-reporting components can affect support and diagnostic workflows. Coordinate with operations and application owners, preserve required diagnostic evidence, and do not treat local access or severity as proof of exploitation.
Evidence To Retain
- Exact product, release stream, package or application version, enabled feature, environment, and accountable owner.
- UTC timestamps, source advisory revision, approved change record, installer or package-manager output, and resulting version.
- Relevant logs and monitoring evidence, test results, exceptions, compensating controls, and rollback decisions.
Related TechGeeks Resources
Authoritative References
Correction policy: If the authority changes affected versions, fixed versions, severity, exploitation information, mitigations, or required action, TechGeeks will update this notice and its verification date.

