Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-44604

Опубликовано: 28 мая 2026
Источник: redhat
CVSS3: 7
EPSS Низкий

Описание

A command injection vulnerability was discovered in the rpmuncompress utility of RPM. When extracting certain archive formats (ZIP, 7z, GEM) to a specified destination directory, the tool inserts the archive's top-level folder name into a shell command without properly sanitizing it. A specially crafted archive containing shell metacharacters in its folder name can execute arbitrary commands as the user running the extraction.

Отчет

This affects RPM source-preparation workflows, posing a risk in build environments. Standard tar extraction is not affected.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Pen Drive Powered by Red Hat Lightspeedpen-drive/pen-drive-scanner-rhel9Under investigation
Red Hat build of Quarkus Native builderrpmUnder investigation
Red Hat Enterprise Linux 10rpmUnder investigation
Red Hat Enterprise Linux 10rust-bootupdUnder investigation
Red Hat Enterprise Linux 6rpmUnder investigation
Red Hat Enterprise Linux 7rpmUnder investigation
Red Hat Enterprise Linux 8rpmUnder investigation
Red Hat Enterprise Linux 9rpmUnder investigation
Red Hat Enterprise Linux 9rust-bootupdUnder investigation
Red Hat OpenShift Container Platform 4rhcosUnder investigation

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-78
https://bugzilla.redhat.com/show_bug.cgi?id=2460967rpm: Command injection in rpmuncompress doUntar() via unescaped archive top-level directory name in popen() shell command

EPSS

Процентиль: 44%
0.00567
Низкий

7 High

CVSS3

Связанные уязвимости

CVSS3: 7
ubuntu
2 месяца назад

A command injection vulnerability was discovered in the `rpmuncompress` utility of RPM. When extracting certain archive formats (ZIP, 7z, GEM) to a specified destination directory, the tool inserts the archive's top-level folder name into a shell command without properly sanitizing it. A specially crafted archive containing shell metacharacters in its folder name can execute arbitrary commands as the user running the extraction.

CVSS3: 7
nvd
2 месяца назад

A command injection vulnerability was discovered in the `rpmuncompress` utility of RPM. When extracting certain archive formats (ZIP, 7z, GEM) to a specified destination directory, the tool inserts the archive's top-level folder name into a shell command without properly sanitizing it. A specially crafted archive containing shell metacharacters in its folder name can execute arbitrary commands as the user running the extraction.

CVSS3: 7
debian
2 месяца назад

A command injection vulnerability was discovered in the `rpmuncompress ...

CVSS3: 7
github
2 месяца назад

A command injection vulnerability was discovered in the `rpmuncompress` utility of RPM. When extracting certain archive formats (ZIP, 7z, GEM) to a specified destination directory, the tool inserts the archive's top-level folder name into a shell command without properly sanitizing it. A specially crafted archive containing shell metacharacters in its folder name can execute arbitrary commands as the user running the extraction.

EPSS

Процентиль: 44%
0.00567
Низкий

7 High

CVSS3