Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-84233

Опубликовано: 01 сент. 2026
Источник: redhat
CVSS3: 7
EPSS Низкий

Описание

A flaw was found in rpm. A local attacker could supply a specially crafted .gem filename containing RPM macro syntax. When a user or automated workflow invokes rpmuncompress -x on this file, the macro expansion occurs during command construction. This allows the attacker to execute arbitrary commands with the privileges of the invoking account, leading to a compromise of confidentiality, integrity, and availability.

Отчет

This issue is considered Moderate severity because, although successful exploitation allows arbitrary command execution with the privileges of the user or workflow invoking rpmuncompress -x (or a build workflow that invokes it via %{__rpmuncompress}), exploitation requires a specially crafted local .gem filename containing RPM macro syntax to be processed by that tool. The vulnerable code is not exposed as a network service and cannot be triggered remotely without a user or automated workflow invoking rpmuncompress on the attacker-controlled filename.

Меры по смягчению последствий

To mitigate this vulnerability, avoid using rpmuncompress -x (or a build workflow that invokes it via %{__rpmuncompress}) on .gem files from untrusted sources. Before extraction, rename .gem files to remove any RPM macro syntax (e.g., %(...)) or utilize an alternative extraction tool that does not expand RPM macros in filenames. In automated environments, implement validation to reject or sanitize untrusted archive names prior to processing

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10rpmAffected
Red Hat Enterprise Linux 6rpmNot affected
Red Hat Enterprise Linux 7rpmNot affected
Red Hat Enterprise Linux 8rpmNot affected
Red Hat Enterprise Linux 9rpmNot affected
Red Hat Hardened ImagesrpmAffected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-78
https://bugzilla.redhat.com/show_bug.cgi?id=2478409rpm: Command Execution via Macro Expansion in `rpmuncompress -x` for Crafted `.gem` Filenames

EPSS

Процентиль: 3%
0.0013
Низкий

7 High

CVSS3

Связанные уязвимости

CVSS3: 7
ubuntu
15 дней назад

(A flaw was found in rpm. A local attacker could supply a specially cra ...)

CVSS3: 7
nvd
15 дней назад

A flaw was found in rpm. A local attacker could supply a specially crafted `.gem` filename containing RPM macro syntax. When a user or automated workflow invokes `rpmuncompress -x` on this file, the macro expansion occurs during command construction. This allows the attacker to execute arbitrary commands with the privileges of the invoking account, leading to a compromise of confidentiality, integrity, and availability.

msrc
9 дней назад

Rpm: command execution via macro expansion in `rpmuncompress -x` for crafted `.gem` filenames

CVSS3: 7
debian
15 дней назад

A flaw was found in rpm. A local attacker could supply a specially cra ...

CVSS3: 7
github
15 дней назад

A flaw was found in rpm. A local attacker could supply a specially crafted `.gem` filename containing RPM macro syntax. When a user or automated workflow invokes `rpmuncompress -x` on this file, the macro expansion occurs during command construction. This allows the attacker to execute arbitrary commands with the privileges of the invoking account, leading to a compromise of confidentiality, integrity, and availability.

EPSS

Процентиль: 3%
0.0013
Низкий

7 High

CVSS3