Описание
A flaw was found in the RPM Package Manager (RPM). A local user could be affected by a heap buffer overflow vulnerability when processing a specially crafted NDB database file. This issue arises from an error in how RPM handles certain calculations during file parsing, leading to an incorrect memory allocation. An attacker could leverage this to cause a denial of service, making the system unavailable.
Отчет
This vulnerability has a Low impact on Red Hat Enterprise Linux and Fedora systems. A heap buffer overflow in RPM's NDB database backend can be triggered by processing a specially crafted NDB database file. However, NDB is not the default RPM database backend in these distributions, which instead utilize SQLite, significantly reducing the attack surface.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Enterprise Linux 10 | rpm | Under investigation | ||
| Red Hat Enterprise Linux 10 | rust-bootupd | Under investigation | ||
| Red Hat Enterprise Linux 6 | rpm | Under investigation | ||
| Red Hat Enterprise Linux 7 | rpm | Under investigation | ||
| Red Hat Enterprise Linux 8 | rpm | Under investigation | ||
| Red Hat Enterprise Linux 9 | rpm | Under investigation | ||
| Red Hat Enterprise Linux 9 | rust-bootupd | Under investigation | ||
| Red Hat Hardened Images | rpm-main-6.0.1-6.2.hum1 | Fixed | RHSA-2026:33507 | 30.06.2026 |
Показывать по
Дополнительная информация
Статус:
EPSS
5.5 Medium
CVSS3
Связанные уязвимости
A flaw was found in the RPM Package Manager (RPM). A local user could be affected by a heap buffer overflow vulnerability when processing a specially crafted NDB database file. This issue arises from an error in how RPM handles certain calculations during file parsing, leading to an incorrect memory allocation. An attacker could leverage this to cause a denial of service, making the system unavailable.
A flaw was found in the RPM Package Manager (RPM). A local user could ...
A flaw was found in the RPM Package Manager (RPM). A local user could be affected by a heap buffer overflow vulnerability when processing a specially crafted NDB database file. This issue arises from an error in how RPM handles certain calculations during file parsing, leading to an incorrect memory allocation. An attacker could leverage this to cause a denial of service, making the system unavailable.
EPSS
5.5 Medium
CVSS3