Impact
A local user may trigger a heap buffer overflow in RPM’s handling of a specially crafted NDB database file. The flaw arises from an incorrect memory allocation during parsing, allowing the attacker to cause a denial of service that renders the system unavailable.
Affected Systems
The vulnerability impacts the RPM package manager in Red Hat Enterprise Linux 6 through 10 and Red Hat Hardened Images. All versions listed in the advisory are affected and require the updater package to be replaced with the fixed release.
Risk and Exploitability
The CVSS score of 5.5 indicates moderate severity; EPSS is not available and the issue is not listed in KEV. Exploitation requires local privileges to supply the malicious NDB file and run RPM, so the risk is limited to systems where an authenticated local user can influence package activities. An attacker can crash the process, causing a denial of service but no code execution.
OpenCVE Enrichment