PT-2026-80891 · Rpm · Rpm

·

CVE-2026-78367

·

Published

2026-08-24

·

Updated

2026-08-24

CVSS v3.1

7.0

High

VectorAV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions RPM (affected versions not specified)
Description An issue exists in the tarball processing of rpmbuild. When operating in tarball mode (such as -ts, -ta, or -tb), the getTarSpec() function in tools/rpmbuild.cc passes a member name from a crafted source archive to rpmExpand() within a %{basename:...} macro expression. This allows an attacker to inject RPM macros, including Lua expressions, leading to arbitrary code execution with the privileges of the user running the process.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Special Elements Injection

Code Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-12712
CVE-2026-78367
ECHO-C708-0D0A-F19B

Affected Products

Rpm