Hi, The following vulnerabilities were published for rpm. CVE-2026-103242[0]: | A heap-based buffer overflow flaw was found in rpm. | RPMTAG_FILESIGNATURES in a crafted, unsigned RPM package's main | header is declared with the wrong header type, causing hex2binv() to | allocate a one-byte buffer and then write the tag's attacker- | controlled, hex-decoded content — of attacker-chosen length — past | the end of that allocation. This is reachable via rpm2cpio, | rpm2archive, and rpm -qlvp on an untrusted package. CVE-2026-95519[1]: | A flaw was found in rpm. An attacker can supply a crafted manifest | file that, when processed by a user or automation using `rpm -q -p` | or similar manifest-processing flows, leads to arbitrary code | execution. This occurs because manifest entries are unexpectedly | macro-expanded before being opened, allowing embedded shell commands | to run with the privileges of the `rpm` process. Successful | exploitation can lead to a full compromise of confidentiality, | integrity, and availability for the affected account. CVE-2026-95520[2]: | A heap-based buffer overflow flaw was found in rpm. Parsing a | symlink entry in an untrusted RPM package whose declared | RPMTAG_LONGFILESIZES value is 0xFFFFFFFFFFFFFFFF causes an integer | overflow in iterReadArchiveNext() that shrinks a buffer allocation | to one byte, after which the payload's independently-controlled cpio | filesize field is used to write attacker-controlled data past the | end of that allocation. This is reachable via rpm2cpio, rpm2archive, | and rpm -qlvp on an untrusted package. CVE-2026-95521[3]: | A command injection flaw was found in rpm. Installing or rebuilding | a source RPM whose source or spec file basenames contain a %() macro | construct causes rpm to execute an attacker-controlled shell command | via popen() while relocating the source file list. This allows | arbitrary command execution as the invoking (typically non-root) | user, simply by installing, rebuilding, or otherwise processing an | untrusted .src.rpm. Unfortunately we have only very light information on the issues at time of writing this bugreport. Can you please investigate and update the bug on reference sto upstream issues please and the upstream status of those? If you fix the vulnerabilities please also make sure to include the CVE (Common Vulnerabilities & Exposures) ids in your changelog entry. For further information see: [0] https://security-tracker.debian.org/tracker/CVE-2026-103242 https://www.cve.org/CVERecord?id=CVE-2026-103242 [1] https://security-tracker.debian.org/tracker/CVE-2026-95519 https://www.cve.org/CVERecord?id=CVE-2026-95519 [2] https://security-tracker.debian.org/tracker/CVE-2026-95520 https://www.cve.org/CVERecord?id=CVE-2026-95520 [3] https://security-tracker.debian.org/tracker/CVE-2026-95521 https://www.cve.org/CVERecord?id=CVE-2026-95521 Regards, Salvatore