Description
A heap-based buffer overflow flaw was found in rpm. RPMTAG_FILESIGNATURES in a crafted, unsigned RPM package's main header is declared with the wrong header type, causing hex2binv() to allocate a one-byte buffer and then write the tag's attacker-controlled, hex-decoded content — of attacker-chosen length — past the end of that allocation. This is reachable via rpm2cpio, rpm2archive, and rpm -qlvp on an untrusted package.
Published: 2026-09-30
Score: 7.1 High
EPSS: n/a
KEV: No
Impact: MEMORY CORRUPTION / POTENTIAL RCE
Action: Patch Immediately
AI Analysis

Impact

A heap‑based buffer overflow occurs in rpm when the RPMTAG_FILESIGNATURES header of a crafted, unsigned RPM is declared with an incorrect header type. The wrong type causes hex2binv() to allocate only a one‑byte buffer and then write the attacker‑controlled, hex‑decoded data of arbitrary length beyond that allocation, leading to memory corruption that could be exploited to hijack execution flow.

Affected Systems

The flaw affects Red Hat Enterprise Linux 10, 6, 7, 8, 9 and Red Hat Hardened Images when they use the vulnerable rpm utility. Any system that processes RPM packages with these operating systems would be impacted.

Risk and Exploitability

The CVSS score of 7.1 indicates a medium severity vulnerability. EPSS is not available and the issue is not listed in the CISA KEV catalogue. The attack vector is reachable locally by exploiting rpm2cpio, rpm2archive or rpm –qlvp against an untrusted or unsigned RPM package, allowing an attacker to trigger the overflow and potentially achieve arbitrary code execution if they can supply a crafted payload.

Generated by OpenCVE AI on September 30, 2026 at 13:27 UTC.

Remediation

Vendor Workaround

Avoid processing or extracting RPM packages from untrusted or unsigned sources. Do not run rpm -qlvp, rpm2cpio, or rpm2archive against RPM files whose origin and integrity cannot be verified.


OpenCVE Recommended Actions

  • Avoid using rpm’s rpm2cpio, rpm2archive or rpm –qlvp commands on any untrusted or unsigned RPM files
  • Verify the integrity and GPG signature of RPM packages before processing them with rpm tools
  • Apply Red Hat security updates or patches that fix the vulnerable rpm package as soon as they are released

Generated by OpenCVE AI on September 30, 2026 at 13:27 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 30 Sep 2026 12:00:00 +0000

Type Values Removed Values Added
Description A heap-based buffer overflow flaw was found in rpm. RPMTAG_FILESIGNATURES in a crafted, unsigned RPM package's main header is declared with the wrong header type, causing hex2binv() to allocate a one-byte buffer and then write the tag's attacker-controlled, hex-decoded content — of attacker-chosen length — past the end of that allocation. This is reachable via rpm2cpio, rpm2archive, and rpm -qlvp on an untrusted package.
Title Rpm: heap-based buffer overflow write in hex2binv() via a mistyped rpmtag_filesignatures header tag
First Time appeared Redhat
Redhat enterprise Linux
Redhat hummingbird
Weaknesses CWE-122
CPEs cpe:/a:redhat:hummingbird:1
cpe:/o:redhat:enterprise_linux:10
cpe:/o:redhat:enterprise_linux:6
cpe:/o:redhat:enterprise_linux:7
cpe:/o:redhat:enterprise_linux:8
cpe:/o:redhat:enterprise_linux:9
Vendors & Products Redhat
Redhat enterprise Linux
Redhat hummingbird
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H'}


Subscriptions

Redhat Enterprise Linux Hummingbird
cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published:

Updated: 2026-09-30T11:50:32.039Z

Reserved: 2026-09-30T10:39:52.447Z

Link: CVE-2026-103242

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-30T12:17:12.653

Modified: 2026-09-30T12:17:12.653

Link: CVE-2026-103242

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-30T13:30:17Z

Weaknesses
  • CWE-122

    Heap-based Buffer Overflow