Macro Injection Vulnerability in rpmbuild Affects Red Hat Products
CVE-2026-78367

7HIGH

What is CVE-2026-78367?

A flaw has been identified in rpmbuild that exposes systems to remote code execution risks. When processing specially crafted tarballs in tarball mode, a maliciously designed tar member name can lead to macro injection. This vulnerability allows attackers to manipulate users into building these harmful tarballs, resulting in the execution of arbitrary code on the system. It underscores the importance of verifying the integrity of tarball contents before processing them to mitigate security threats.

References

CVSS V3.1

Score:
7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Red Hat would like to thank SANDIPAN ROY (RED HAT) for reporting this issue.
.