Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-84838

Опубликовано: 02 сент. 2026
Источник: redhat
CVSS3: 7.8
EPSS Низкий

Описание

A flaw was found in rpmuncompress. This command injection vulnerability allows a local attacker to execute arbitrary commands. This occurs when rpmuncompress processes a specially crafted archive filename containing shell metacharacters, which are not properly escaped before being passed to shell command strings. Successful exploitation requires user interaction, where a user or automated workflow invokes rpmuncompress on the malicious file, leading to high impact on the confidentiality, integrity, and availability of data accessible to the invoking user.

Отчет

This issue is considered Moderate severity because, although successful exploitation allows arbitrary command execution with the privileges of the user running rpmuncompress (or a build workflow that invokes it via %{__rpmuncompress}), exploitation requires a specially crafted local archive filename to be processed by that tool. The vulnerable code is not exposed as a network service and cannot be triggered remotely without a user or automated workflow invoking rpmuncompress on the attacker-controlled filename.

Меры по смягчению последствий

To mitigate this issue, avoid processing untrusted archive filenames with rpmuncompress or any workflows that invoke %{__rpmuncompress}. Before any build or extraction steps, rename source and patch archives to remove any shell metacharacters from their filenames.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10rpmAffected
Red Hat Enterprise Linux 6rpmNot affected
Red Hat Enterprise Linux 7rpmNot affected
Red Hat Enterprise Linux 8rpmNot affected
Red Hat Enterprise Linux 9rpmNot affected
Red Hat Hardened ImagesrpmAffected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-78
https://bugzilla.redhat.com/show_bug.cgi?id=2462222rpm: Command injection in rpmuncompress via unescaped filenames passed to popen()

EPSS

Процентиль: 62%
0.01034
Низкий

7.8 High

CVSS3

Связанные уязвимости

CVSS3: 7.8
ubuntu
13 дней назад

A flaw was found in rpmuncompress. This command injection vulnerability allows a local attacker to execute arbitrary commands. This occurs when rpmuncompress processes a specially crafted archive filename containing shell metacharacters, which are not properly escaped before being passed to shell command strings. Successful exploitation requires user interaction, where a user or automated workflow invokes rpmuncompress on the malicious file, leading to high impact on the confidentiality, integrity, and availability of data accessible to the invoking user.

CVSS3: 7.8
nvd
14 дней назад

A flaw was found in rpmuncompress. This command injection vulnerability allows a local attacker to execute arbitrary commands. This occurs when rpmuncompress processes a specially crafted archive filename containing shell metacharacters, which are not properly escaped before being passed to shell command strings. Successful exploitation requires user interaction, where a user or automated workflow invokes rpmuncompress on the malicious file, leading to high impact on the confidentiality, integrity, and availability of data accessible to the invoking user.

msrc
9 дней назад

Rpm: command injection in rpmuncompress via unescaped filenames passed to popen()

CVSS3: 7.8
debian
14 дней назад

A flaw was found in rpmuncompress. This command injection vulnerabilit ...

CVSS3: 7.8
github
14 дней назад

A flaw was found in rpmuncompress. This command injection vulnerability allows a local attacker to execute arbitrary commands. This occurs when rpmuncompress processes a specially crafted archive filename containing shell metacharacters, which are not properly escaped before being passed to shell command strings. Successful exploitation requires user interaction, where a user or automated workflow invokes rpmuncompress on the malicious file, leading to high impact on the confidentiality, integrity, and availability of data accessible to the invoking user.

EPSS

Процентиль: 62%
0.01034
Низкий

7.8 High

CVSS3