CVE-2015-1862

HIGH

abrt < 2.2.0 - Local Privilege Escalation via Race Condition in Crash Reporting

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 2 public exploits for CVE-2015-1862. PoCs published by Tavis Ormandy.

AI-analyzed exploit summary This exploit leverages a race condition in ABRT (Automatic Bug Reporting Tool) on Fedora 21 to gain ownership of arbitrary files by manipulating symlinks during crash report generation. It uses inotify to monitor ABRT's temporary directory and attempts to replace the 'maps' file with a symlink to the target file.

Description

The crash reporting feature in Abrt allows local users to gain privileges by leveraging an execve by root after a chroot into a user-specified directory in a namedspaced environment.

Exploits (2)

exploitdb WORKING POC VERIFIED
by Tavis Ormandy · clocallinux
https://www.exploit-db.com/exploits/36747

This exploit leverages a race condition in ABRT (Automatic Bug Reporting Tool) on Fedora 21 to gain ownership of arbitrary files by manipulating symlinks during crash report generation. It uses inotify to monitor ABRT's temporary directory and attempts to replace the 'maps' file with a symlink to the target file.

Classification
Working Poc 100%
Attack Type
Lpe
Complexity
Complex
Reliability
Racy
Target: ABRT on Fedora 21
No auth needed
Prerequisites: Local access to a vulnerable Fedora 21 system · ABRT service running
devstral-2 · analyzed Feb 16, 2026 Full analysis →
exploitdb WORKING POC VERIFIED
by Tavis Ormandy · clocallinux
https://www.exploit-db.com/exploits/36746

This exploit leverages CVE-2015-1862 in Abrt (and CVE-2015-1318 in Apport) by creating a chroot environment with hard links to the exploit binary, then triggering a core dump in a new PID/user namespace to gain root privileges. It checks for static compilation and spawns a root shell upon successful exploitation.

Classification
Working Poc 100%
Attack Type
Lpe
Complexity
Complex
Reliability
Reliable
Target: Abrt (Fedora) and Apport (Ubuntu) core dump handlers
No auth needed
Prerequisites: Static compilation of the exploit · Presence of Abrt or Apport core dump handlers
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (10)

Core 10
Core References
Issue Tracking, Third Party Advisory x_refsource_confirm
https://bugzilla.redhat.com/show_bug.cgi?id=1211223
Mailing List mailing-list x_refsource_mlist
http://www.openwall.com/lists/oss-security/2015/04/14/4
Exploit, Third Party Advisory, VDB Entry x_refsource_misc
http://packetstormsecurity.com/files/131422/Fedora-abrt-Race-Condition.html
Exploit, Third Party Advisory, VDB Entry exploit x_refsource_exploit-db
https://www.exploit-db.com/exploits/36746/
Exploit, Third Party Advisory, VDB Entry x_refsource_misc
http://packetstormsecurity.com/files/131429/Abrt-Apport-Race-Condition-Symlink.html
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/74263
Exploit, Third Party Advisory, VDB Entry exploit x_refsource_exploit-db
https://www.exploit-db.com/exploits/36747/
Issue Tracking, Patch, Third Party Advisory x_refsource_confirm
https://github.com/abrt/abrt/pull/810
Exploit, Third Party Advisory, VDB Entry x_refsource_misc
http://packetstormsecurity.com/files/131423/Linux-Apport-Abrt-Local-Root-Exploit.html
Mailing List, Third Party Advisory mailing-list x_refsource_fulldisc
http://seclists.org/fulldisclosure/2015/Apr/34

Scores

CVSS v3 7.0
EPSS 0.0541
EPSS Percentile 90.4%
Attack Vector LOCAL
CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-362
Status published
Products (1)
abrt_project/abrt < 2.2.0
Published Feb 09, 2018
Tracked Since Feb 18, 2026