Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-44605

Опубликовано: 28 мая 2026
Источник: redhat
CVSS3: 5.5
EPSS Низкий

Описание

A flaw was found in the RPM Package Manager (RPM). A local user could be affected by a heap buffer overflow vulnerability when processing a specially crafted NDB database file. This issue arises from an error in how RPM handles certain calculations during file parsing, leading to an incorrect memory allocation. An attacker could leverage this to cause a denial of service, making the system unavailable.

Отчет

This vulnerability has a Low impact on Red Hat Enterprise Linux and Fedora systems. A heap buffer overflow in RPM's NDB database backend can be triggered by processing a specially crafted NDB database file. However, NDB is not the default RPM database backend in these distributions, which instead utilize SQLite, significantly reducing the attack surface.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10rpmUnder investigation
Red Hat Enterprise Linux 10rust-bootupdUnder investigation
Red Hat Enterprise Linux 6rpmUnder investigation
Red Hat Enterprise Linux 7rpmUnder investigation
Red Hat Enterprise Linux 8rpmUnder investigation
Red Hat Enterprise Linux 9rpmUnder investigation
Red Hat Enterprise Linux 9rust-bootupdUnder investigation
Red Hat Hardened Imagesrpm-main-6.0.1-6.2.hum1FixedRHSA-2026:3350730.06.2026

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-190
https://bugzilla.redhat.com/show_bug.cgi?id=2482481rpm: heap buffer overflow in NDB slot table parsing

EPSS

Процентиль: 3%
0.00135
Низкий

5.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.5
ubuntu
около 1 месяца назад

[Unknown description]

CVSS3: 5.5
nvd
3 дня назад

A flaw was found in the RPM Package Manager (RPM). A local user could be affected by a heap buffer overflow vulnerability when processing a specially crafted NDB database file. This issue arises from an error in how RPM handles certain calculations during file parsing, leading to an incorrect memory allocation. An attacker could leverage this to cause a denial of service, making the system unavailable.

CVSS3: 5.5
debian
3 дня назад

A flaw was found in the RPM Package Manager (RPM). A local user could ...

CVSS3: 5.5
github
3 дня назад

A flaw was found in the RPM Package Manager (RPM). A local user could be affected by a heap buffer overflow vulnerability when processing a specially crafted NDB database file. This issue arises from an error in how RPM handles certain calculations during file parsing, leading to an incorrect memory allocation. An attacker could leverage this to cause a denial of service, making the system unavailable.

EPSS

Процентиль: 3%
0.00135
Низкий

5.5 Medium

CVSS3