Heap-Based Buffer Overflow Vulnerability in RPM by Red Hat
CVE-2026-103242
7.1HIGH
What is CVE-2026-103242?
A vulnerability in RPM has been identified that allows for a heap-based buffer overflow when processing crafted, unsigned RPM packages. Specifically, the RPMTAG_FILESIGNATURES in the main header is incorrectly declared, which then leads to an allocation of insufficient buffer size. This flaw can be exploited through commands such as rpm2cpio, rpm2archive, and rpm -qlvp, enabling attackers to write beyond the allocated buffer by providing specially crafted content. The implications of this security flaw necessitate immediate attention to protect systems from potential exploitation.
References
CVSS V3.1
Score:
7.1
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Red Hat would like to thank Calif.io for reporting this issue.