Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

openSUSE-SU-2026:21856-1

Опубликовано: 16 сент. 2026
Источник: suse-cvrf

Описание

Security update for rpm

This update for rpm fixes the following issues:

Changes in rpm:

  • split imaevmsign plugin into a multibuild flavor

Changes in rpm:

  • Add Requires: (rpm-plugin-selinux if selinux-policy)
  • harden ndb code [bsc#1269584] [CVE-2026-44605]
  • split all plugins into subpackages
    • this allows for an easy way to get rid of a plugin, it's also what other distributions do
  • make the imaevmsign plugin build in a multibuild flavor
  • rpm2archive: use size 0 for hardlinked files as bnew versions of gnu tar reject non-zero sizes [bsc#1269150]
  • backport fix for add_sysuser macro [bsc#1269571]
  • backport rpmuncompress security fix [bsc#1268747] [CVE-2026-44604]
  • switch from rpmpgp_legacy to libpgpr
    • multiple bug fixes, support for v5 and v6 signatures
  • turn on imaevm file signature support and move the imaevm code that needs the libimaevm library into a plugin. Put this plugin into a new "rpm-imaevmsign" subpackage. [jsc#PED-7246]
  • Fix "unexpected EOF" when using rpmbuild to install ELF binaries due to syntax error in /usr/lib/rpm/brp-strip. (boo#1259215)
  • Remove /var/lib/rpm migration scripting, retain an error if old location is found
  • Use systemd-tmpfiles to create & maintain /var/lib/rpm symlink (boo#1253139)
  • flush scriptlet notification messages in --runposttrans
    • needed to fix leaking tmp files [bsc#1218459]
    • added "rpm_flushes_runposttrans" provides for libzypp

Список пакетов

openSUSE Leap 16.0
librpmbuild10-4.20.1-160000.3.1
python313-rpm-4.20.1-160000.3.1
rpm-4.20.1-160000.3.1
rpm-build-4.20.1-160000.3.1
rpm-devel-4.20.1-160000.3.1
rpm-plugin-fapolicyd-4.20.1-160000.3.1
rpm-plugin-ima-4.20.1-160000.3.1
rpm-plugin-imaevmsign-4.20.1-160000.3.1
rpm-plugin-prioreset-4.20.1-160000.3.1
rpm-plugin-selinux-4.20.1-160000.3.1
rpm-plugin-syslog-4.20.1-160000.3.1
rpm-plugin-unshare-4.20.1-160000.3.1

Описание

A command injection vulnerability was discovered in the `rpmuncompress` utility of RPM. When extracting certain archive formats (ZIP, 7z, GEM) to a specified destination directory, the tool inserts the archive's top-level folder name into a shell command without properly sanitizing it. A specially crafted archive containing shell metacharacters in its folder name can execute arbitrary commands as the user running the extraction.


Затронутые продукты
openSUSE Leap 16.0:librpmbuild10-4.20.1-160000.3.1
openSUSE Leap 16.0:python313-rpm-4.20.1-160000.3.1
openSUSE Leap 16.0:rpm-4.20.1-160000.3.1
openSUSE Leap 16.0:rpm-build-4.20.1-160000.3.1

Ссылки

Описание

A flaw was found in the RPM Package Manager (RPM). A local user could be affected by a heap buffer overflow vulnerability when processing a specially crafted NDB database file. This issue arises from an error in how RPM handles certain calculations during file parsing, leading to an incorrect memory allocation. An attacker could leverage this to cause a denial of service, making the system unavailable.


Затронутые продукты
openSUSE Leap 16.0:librpmbuild10-4.20.1-160000.3.1
openSUSE Leap 16.0:python313-rpm-4.20.1-160000.3.1
openSUSE Leap 16.0:rpm-4.20.1-160000.3.1
openSUSE Leap 16.0:rpm-build-4.20.1-160000.3.1

Ссылки