Sceawere
Vulnerability Detail
CVE-2026-95520UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
RPM Heap Buffer Overflow Vulnerability
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 7.1
- Creation Date
- 13h ago
- Vendor
- Red Hat
- Product
- Red Hat Enterprise Linux 10
- Attack Type
- Out-of-bounds Write
- Vector String
- CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H
- Attack Complexity
- LOW
Narrative and Response
Description
A heap-based buffer overflow flaw was found in rpm. Parsing a symlink entry in an untrusted RPM package whose declared RPMTAG_LONGFILESIZES value is 0xFFFFFFFFFFFFFFFF causes an integer overflow in iterReadArchiveNext() that shrinks a buffer allocation to one byte, after which the payload's independently-controlled cpio filesize field is used to write attacker-controlled data past the end of that allocation. This is reachable via rpm2cpio, rpm2archive, and rpm -qlvp on an untrusted package.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "7.1",
"pubDate": "2026-09-29T12:17:12.650Z",
"pubdate": "2026-09-29T12:17:12.650Z",
"executiveSummary": "A critical heap-based buffer overflow vulnerability exists within the rpm package management utility. The flaw is triggered during the parsing of symlink entries within maliciously crafted, untrusted RPM packages. By manipulating specific metadata fields, an attacker can induce an integer overflow, leading to an undersized heap allocation. This condition facilitates subsequent out-of-bounds memory writes using attacker-supplied data.\nThe vulnerability affects systems processing untrusted RPM packages using utilities such as rpm2cpio, rpm2archive, or rpm -qlvp. Successful exploitation allows an attacker to execute arbitrary code or cause a denial-of-service by crashing the affected process. This flaw poses a significant risk to package management infrastructure and any automated system that parses external RPM files without prior validation. Exploitation does not require prior authentication or elevated privileges, provided the attacker can convince a user or automated system to process a malformed RPM package.",
"technicalDetails": "The vulnerability originates in the iterReadArchiveNext() function within the rpm codebase, which is responsible for processing archive entries during the extraction or inspection of RPM packages. The flaw stems from improper handling of the RPMTAG_LONGFILESIZES metadata tag during the parsing of symlink entries.\nThe attack flow begins when the parser encounters a crafted RPM file where the RPMTAG_LONGFILESIZES field is set to 0xFFFFFFFFFFFFFFFF. When this value is processed, an integer overflow occurs during the buffer size calculation. This overflow causes the memory allocation logic to wrap around, resulting in a buffer allocation of only one byte for a data structure intended to hold larger payloads.\nOnce the undersized heap buffer is allocated, the exploitation proceeds by leveraging an independently controlled cpio filesize field embedded within the RPM payload. Because the system believes the destination buffer is appropriate for the incoming data—despite the underlying allocation being truncated to a single byte—the subsequent read operation performs an out-of-bounds write.\nThe attacker-controlled payload is then written past the boundaries of the heap-allocated memory. By carefully crafting the RPM archive, an attacker can overwrite adjacent heap chunks, potentially corrupting control structures, function pointers, or data objects. This manipulation allows for arbitrary code execution in the context of the user running the rpm utility. The impact is maximized because the vulnerability is reachable via standard forensic and extraction tools like rpm2cpio and rpm -qlvp, which are frequently utilized in security analysis and system administration workflows. No authentication is required to initiate the attack; the primary vector is the consumption of a malicious package by an unsuspecting user or system process."
}