Command Injection Vulnerability in RPM by Red Hat
CVE-2026-84837
7.8HIGH
What is CVE-2026-84837?
A command injection vulnerability exists in RPM that allows attackers to manipulate the path or filename of a tarball processed by the rpmbuild -t* command. This flaw is particularly concerning in automated build systems and continuous integration (CI) workflows where external artifact names are consumed. By exploiting this vulnerability, an attacker can execute arbitrary commands with the privileges of the build user, potentially leading to information disclosure or disruption of the build environment. It is crucial for organizations using RPM in their workflows to assess their environments and implement necessary mitigations.
References
CVSS V3.1
Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
This issue was discovered by Found by AISLE in partnership with Red Hat.