Sceawere
Vulnerability Detail
CVE-2026-103242UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
RPM Heap Overflow Vulnerability
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 7.1
- Creation Date
- 4h ago
- Vendor
- Red Hat
- Product
- Red Hat Enterprise Linux 10
- Attack Type
- Heap-based Buffer Overflow
- Vector String
- CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H
- Attack Complexity
- LOW
Narrative and Response
Description
A heap-based buffer overflow flaw was found in rpm. RPMTAG_FILESIGNATURES in a crafted, unsigned RPM package's main header is declared with the wrong header type, causing hex2binv() to allocate a one-byte buffer and then write the tag's attacker-controlled, hex-decoded content — of attacker-chosen length — past the end of that allocation. This is reachable via rpm2cpio, rpm2archive, and rpm -qlvp on an untrusted package.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "7.1",
"pubDate": "2026-09-30T12:17:12.653Z",
"pubdate": "2026-09-30T12:17:12.653Z",
"executiveSummary": "A critical heap-based buffer overflow vulnerability exists within the RPM package manager's handling of specific header tags. The flaw is triggered when processing a malformed, unsigned RPM package containing an incorrectly declared RPMTAG_FILESIGNATURES tag. This vulnerability allows an attacker to manipulate memory allocation and write arbitrary hex-decoded data beyond the boundaries of a heap-allocated buffer.\nThe vulnerability affects systems utilizing the rpm utility, specifically exposing components such as rpm2cpio, rpm2archive, and the rpm query functionality (rpm -qlvp). Successful exploitation leads to memory corruption, which can result in application crashes (Denial of Service) or potential arbitrary code execution under the context of the user running the command.\nExploitation requires no authentication, as the flaw is triggered by the ingestion of an untrusted, maliciously crafted RPM package. The risk is significant for automated systems, repository mirrors, or users performing manual inspections of external RPM files, as the vulnerability is triggered upon the parsing of the file's main header.",
"technicalDetails": "The root cause of this vulnerability lies in an improper type declaration within the RPM package's main header for the RPMTAG_FILESIGNATURES tag. When the RPM library processes this tag, it invokes the hex2binv() function to decode the associated hex data. Due to the manipulated header type declaration, the system misinterprets the required storage size for the binary output of the hex decoding process.\nSpecifically, the incorrect declaration causes hex2binv() to allocate a heap buffer of only one byte. The function then proceeds to write the hex-decoded contents of the tag into this insufficient buffer. Because the length of the attacker-controlled content is not validated against this constrained allocation, the process performs an out-of-bounds write operation, overwriting adjacent heap memory.\nThe attack flow proceeds as follows: First, an attacker constructs a maliciously crafted RPM package. Inside the package's main header, the RPMTAG_FILESIGNATURES tag is inserted with a header type that forces the allocation logic to truncate the buffer to a single byte. The attacker then provides a payload consisting of a hex-encoded string of arbitrary length. Upon calling tools such as rpm2cpio or rpm -qlvp on this package, the library parses the header, triggers the flawed heap allocation, and then executes the hex-decoded payload writing beyond the allocated memory block.\nBecause these tools are frequently used to inspect packages from untrusted sources, the exposure is high. The payload behavior is limited by the ability to influence heap state, but the ability to overwrite heap metadata or adjacent objects provides a primitive for potential control-flow hijacking. There are no authentication requirements, as the vulnerability manifests during the standard package inspection phase performed by the rpm library. This memory corruption vulnerability represents a serious threat to package integrity verification processes and general system security, as it bypasses standard validation checks by exploiting the parser logic itself."
}