PT-2026-84293 · Rpm · Rpm
CVSS v3.1
7.0
High
| Vector | AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
rpm (affected versions not specified)
Description
A flaw exists in the
rpmuncompress -x command where the command line is constructed using the input filename. A local attacker can provide a specially crafted .gem filename containing RPM macro syntax, which triggers macro expansion during the command construction process. This allows the execution of arbitrary commands with the privileges of the account invoking the command, potentially compromising confidentiality, integrity, and availability. Systems that do not use rpmuncompress on untrusted filenames are not impacted.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Avoid invoking
rpmuncompress -x on untrusted filenames.OS Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Rpm