#1149951 rpm: CVE-2026-103242 CVE-2026-95519 CVE-2026-95520 CVE-2026-95521

Package:
src:rpm
Source:
src:rpm
Submitter:
Salvatore Bonaccorso
Date:
2026-10-04 18:37:04 UTC
Severity:
normal
Tags:
#1149951#5
Date:
2026-10-04 18:35:22 UTC
From:
To:
Hi,

The following vulnerabilities were published for rpm.

CVE-2026-103242[0]:
| A heap-based buffer overflow flaw was found in rpm.
| RPMTAG_FILESIGNATURES in a crafted, unsigned RPM package's main
| header is declared with the wrong header type, causing hex2binv() to
| allocate a one-byte buffer and then write the tag's attacker-
| controlled, hex-decoded content — of attacker-chosen length — past
| the end of that allocation. This is reachable via rpm2cpio,
| rpm2archive, and rpm -qlvp on an untrusted package.


CVE-2026-95519[1]:
| A flaw was found in rpm. An attacker can supply a crafted manifest
| file that, when processed by a user or automation using `rpm -q -p`
| or similar manifest-processing flows, leads to arbitrary code
| execution. This occurs because manifest entries are unexpectedly
| macro-expanded before being opened, allowing embedded shell commands
| to run with the privileges of the `rpm` process. Successful
| exploitation can lead to a full compromise of confidentiality,
| integrity, and availability for the affected account.


CVE-2026-95520[2]:
| A heap-based buffer overflow flaw was found in rpm. Parsing a
| symlink entry in an untrusted RPM package whose declared
| RPMTAG_LONGFILESIZES value is 0xFFFFFFFFFFFFFFFF causes an integer
| overflow in iterReadArchiveNext() that shrinks a buffer allocation
| to one byte, after which the payload's independently-controlled cpio
| filesize field is used to write attacker-controlled data past the
| end of that allocation. This is reachable via rpm2cpio, rpm2archive,
| and rpm -qlvp on an  untrusted package.


CVE-2026-95521[3]:
| A command injection flaw was found in rpm. Installing or rebuilding
| a source RPM whose source or spec file basenames contain a %() macro
| construct causes rpm to execute an attacker-controlled shell command
| via popen() while relocating the source file list. This allows
| arbitrary command execution as the invoking (typically non-root)
| user, simply by installing, rebuilding, or otherwise processing an
| untrusted .src.rpm.

Unfortunately we have only very light information on the issues at
time of writing this bugreport. Can you please investigate and update
the bug on reference sto upstream issues please and the upstream
status of those?

If you fix the vulnerabilities please also make sure to include the
CVE (Common Vulnerabilities & Exposures) ids in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2026-103242
https://www.cve.org/CVERecord?id=CVE-2026-103242
[1] https://security-tracker.debian.org/tracker/CVE-2026-95519
https://www.cve.org/CVERecord?id=CVE-2026-95519
[2] https://security-tracker.debian.org/tracker/CVE-2026-95520
https://www.cve.org/CVERecord?id=CVE-2026-95520
[3] https://security-tracker.debian.org/tracker/CVE-2026-95521
https://www.cve.org/CVERecord?id=CVE-2026-95521

Regards,
Salvatore