Source: rpm
Version: 6.1.0-1
Severity: important
Tags: security upstream
X-Debbugs-Cc: [email protected], Debian Security Team <[email protected]>

Hi,

The following vulnerabilities were published for rpm.

Unfortunately there are not much additional information available, can
you please research for the individual CVEs if there is any other
project reference to issues and/or fixing commits (apart the for now
only in Red Hat bugzilla found information)?

CVE-2026-44605[0]:
| A flaw was found in the RPM Package Manager (RPM). A local user
| could be affected by a heap buffer overflow vulnerability when
| processing a specially crafted NDB database file. This issue arises
| from an error in how RPM handles certain calculations during file
| parsing, leading to an incorrect memory allocation. An attacker
| could leverage this to cause a denial of service, making the system
| unavailable.


CVE-2026-84233[1]:
| A flaw was found in rpm. A local attacker could supply a specially
| crafted `.gem` filename containing RPM macro syntax. When a user or
| automated workflow invokes `rpmuncompress -x` on this file, the
| macro expansion occurs during command construction. This allows the
| attacker to execute arbitrary commands with the privileges of the
| invoking account, leading to a compromise of confidentiality,
| integrity, and availability.


CVE-2026-84837[2]:
| A flaw was found in rpm. An attacker can exploit a command injection
| vulnerability by influencing the path or filename of a tarball
| processed by `rpmbuild -t*` to include shell metacharacters. This is
| particularly relevant in automated build or continuous integration
| (CI) workflows that ingest externally supplied artifact names.
| Successful exploitation allows for arbitrary command execution with
| the privileges of the build user, which could lead to information
| disclosure or disruption of the build environment.


CVE-2026-84838[3]:
| A flaw was found in rpmuncompress. This command injection
| vulnerability allows a local attacker to execute arbitrary commands.
| This occurs when rpmuncompress processes a specially crafted archive
| filename containing shell metacharacters, which are not properly
| escaped before being passed to shell command strings. Successful
| exploitation requires user interaction, where a user or automated
| workflow invokes rpmuncompress on the malicious file, leading to
| high impact on the confidentiality, integrity, and availability of
| data accessible to the invoking user.


If you fix the vulnerabilities please also make sure to include the
CVE (Common Vulnerabilities & Exposures) ids in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2026-44605
    https://www.cve.org/CVERecord?id=CVE-2026-44605
[1] https://security-tracker.debian.org/tracker/CVE-2026-84233
    https://www.cve.org/CVERecord?id=CVE-2026-84233
[2] https://security-tracker.debian.org/tracker/CVE-2026-84837
    https://www.cve.org/CVERecord?id=CVE-2026-84837
[3] https://security-tracker.debian.org/tracker/CVE-2026-84838
    https://www.cve.org/CVERecord?id=CVE-2026-84838

Please adjust the affected versions in the BTS as needed.

Regards,
Salvatore

Reply via email to