PT-2026-103122 · Red Hat · Rpm

CVE-2026-103242

·

Published

2026-09-30

·

Updated

2026-09-30

CVSS v3.1

7.1

High

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H
Name of the Vulnerable Software and Affected Versions rpm versions RHEL 8 through 10
Description A heap-based buffer overflow occurs when rpm mis-parses the RPMTAG FILESIGNATURES tag in a crafted, unsigned RPM package's main header. If the tag is declared with an incorrect header type, the hex2binv() function allocates a one-byte buffer and subsequently writes attacker-controlled, hex-decoded content of an arbitrary length beyond the allocated memory. This issue is reachable when processing untrusted packages using the rpm2cpio and rpm2archive utilities, or the rpm -qlvp command.
Recommendations For RHEL versions 8 through 10, update the rpm package to a version that corrects the header type parsing in the hex2binv() function.

Fix

Heap Based Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-103242

Affected Products

Rpm