CVE-2015-3315

HIGH

ABRT raceabrt Privilege Escalation

Title source: metasploit
STIX 2.1

Exploitation Summary

EIP tracks 3 public exploits for CVE-2015-3315. PoCs published by Metasploit, Tavis Ormandy, Tavis Ormandy, bcoles, including Metasploit module exploits/linux/local/abrt_raceabrt_priv_esc.

AI-analyzed exploit summary This Metasploit module exploits a race condition in ABRT (CVE-2015-3315) to escalate privileges by changing ownership of /etc/passwd and adding a new root user. It uses a symlink attack on '/var/tmp/abrt/*/maps' to achieve this.

Description

Automatic Bug Reporting Tool (ABRT) allows local users to read, change the ownership of, or have other unspecified impact on arbitrary files via a symlink attack on (1) /var/tmp/abrt/*/maps, (2) /tmp/jvm-*/hs_error.log, (3) /proc/*/exe, (4) /etc/os-release in a chroot, or (5) an unspecified root directory related to librpm.

Exploits (3)

exploitdb WORKING POC VERIFIED
by Metasploit · rubylocallinux
https://www.exploit-db.com/exploits/44097

This Metasploit module exploits a race condition in ABRT (CVE-2015-3315) to escalate privileges by changing ownership of /etc/passwd and adding a new root user. It uses a symlink attack on '/var/tmp/abrt/*/maps' to achieve this.

Classification
Working Poc 100%
Attack Type
Lpe
Complexity
Moderate
Reliability
Racy
Target: ABRT (Automatic Bug Reporting Tool) versions 2.1.5-1.fc19, 2.2.1-1.fc19, 2.2.2-2.fc20
No auth needed
Prerequisites: Local access to a vulnerable Fedora system with ABRT configured as the crash handler · Write permissions in a directory (default: /tmp) · /etc/passwd not being immutable
devstral-2 · analyzed Feb 16, 2026 Full analysis →
exploitdb WORKING POC VERIFIED
by Tavis Ormandy · clocallinux
https://www.exploit-db.com/exploits/36747

This exploit leverages a race condition in ABRT (Automatic Bug Reporting Tool) on Fedora 21 to gain ownership of arbitrary files by manipulating symlinks during crash report generation. It uses inotify to monitor ABRT's temporary directory and attempts to replace the 'maps' file with a symlink to the target file.

Classification
Working Poc 100%
Attack Type
Lpe
Complexity
Complex
Reliability
Racy
Target: ABRT on Fedora 21
No auth needed
Prerequisites: Local access to a vulnerable Fedora 21 system · ABRT service running
devstral-2 · analyzed Feb 16, 2026 Full analysis →
metasploit WORKING POC EXCELLENT
by Tavis Ormandy, bcoles · rubypoc
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/linux/local/abrt_raceabrt_priv_esc.rb

This Metasploit module exploits a race condition in ABRT (CVE-2015-3315) to escalate privileges by changing ownership of /etc/passwd and adding a new root user. It uses a symlink attack on /var/tmp/abrt/*/maps to achieve this.

Classification
Working Poc 100%
Attack Type
Lpe
Complexity
Moderate
Reliability
Racy
Target: ABRT (Automatic Bug Reporting Tool) versions 2.1.5-1.fc19, 2.1.11-12.el7, 2.2.1-1.fc19, 2.2.2-2.fc20, 2.3.0-3.fc21
No auth needed
Prerequisites: Local access to a vulnerable Linux system with ABRT configured as the crash handler · ABRT service (abrt-ccpp) running · Write access to a directory (default: /tmp)
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (11)

Core 11
Core References
Issue Tracking, Third Party Advisory, VDB Entry x_refsource_confirm
https://bugzilla.redhat.com/show_bug.cgi?id=1211835
Mailing List, Third Party Advisory mailing-list x_refsource_mlist
http://www.openwall.com/lists/oss-security/2015/04/16/12
Mailing List, Third Party Advisory mailing-list x_refsource_mlist
http://www.openwall.com/lists/oss-security/2015/04/14/4
Third Party Advisory vendor-advisory x_refsource_redhat
http://rhn.redhat.com/errata/RHSA-2015-1083.html
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/75117
Exploit, Third Party Advisory exploit x_refsource_exploit-db
https://www.exploit-db.com/exploits/44097/
Vendor Advisory vendor-advisory x_refsource_redhat
http://rhn.redhat.com/errata/RHSA-2015-1210.html

Scores

CVSS v3 7.8
EPSS 0.0534
EPSS Percentile 90.3%
Attack Vector LOCAL
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-59
Status published
Products (1)
redhat/automatic_bug_reporting_tool
Published Jun 26, 2017
Tracked Since Feb 18, 2026