Impact
A heap‑based buffer overflow occurs in rpm when the RPMTAG_FILESIGNATURES header of a crafted, unsigned RPM is declared with an incorrect header type. The wrong type causes hex2binv() to allocate only a one‑byte buffer and then write the attacker‑controlled, hex‑decoded data of arbitrary length beyond that allocation, leading to memory corruption that could be exploited to hijack execution flow.
Affected Systems
The flaw affects Red Hat Enterprise Linux 10, 6, 7, 8, 9 and Red Hat Hardened Images when they use the vulnerable rpm utility. Any system that processes RPM packages with these operating systems would be impacted.
Risk and Exploitability
The CVSS score of 7.1 indicates a medium severity vulnerability. EPSS is not available and the issue is not listed in the CISA KEV catalogue. The attack vector is reachable locally by exploiting rpm2cpio, rpm2archive or rpm –qlvp against an untrusted or unsigned RPM package, allowing an attacker to trigger the overflow and potentially achieve arbitrary code execution if they can supply a crafted payload.
OpenCVE Enrichment