Import Source
https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-90101.json
JSON Data
https://api.osv.dev/v1/vulns/AZL-90101
Upstream
  • CVE-2026-54231
Published
2026-06-13T03:16:21Z
Modified
2026-08-31T05:26:07Z
Summary
CVE-2026-54231 affecting package libreport 2.17.15-1
Details

A content injection vulnerability was found in the ABRT post-create event handler scripts in libreport. The event script queries the systemd journal for log entries matching the crashed process and writes the results to files in the dump directory without sanitizing embedded control characters. A local user can inject arbitrary content into the journal output by embedding newline characters in syslog messages, controlling the content that root writes to dump directory files.

References

Affected packages

Azure Linux:3 / libreport

Package

Name
libreport
Purl
pkg:rpm/azure-linux/libreport

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Last affected
2.17.15-1

Database specific

source
"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-90101.json"