Local Command Execution Vulnerability in RPM by Red Hat
CVE-2026-84233
7HIGH
What is CVE-2026-84233?
A vulnerability exists in RPM where a local attacker can craft a .gem filename containing specific RPM macro syntax. This issue arises when the command rpmuncompress -x is executed on such a file, leading to macro expansion during the command's construction. This opens up the potential for the attacker to execute arbitrary commands with the privileges of the user or automated workflow that invokes the command, thereby compromising the system's confidentiality, integrity, and availability.
References
CVSS V3.1
Score:
7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
This issue was discovered by Found by AISLE in partnership with Red Hat.