Heap Buffer Overflow in RPM Package Manager Affecting Red Hat Products
CVE-2026-44605

5.5MEDIUM

What is CVE-2026-44605?

A significant security issue has been identified in the RPM Package Manager that can lead to a heap buffer overflow when processing specially crafted NDB database files. This flaw occurs due to improper handling of specific calculations during file parsing, resulting in incorrect memory allocation. Attackers could exploit this vulnerability locally to trigger a denial of service, potentially rendering the system unavailable and impacting overall operational integrity.

Affected Version(s)

Red Hat Hardened Images 6.0.1-6.2.hum1

References

CVSS V3.1

Score:
5.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.