Command Injection Vulnerability in rpmuncompress Affects Red Hat Products
CVE-2026-84838
7.8HIGH
What is CVE-2026-84838?
A vulnerability exists in the rpmuncompress utility that allows local attackers to execute arbitrary commands via crafted archive filenames. The flaw arises from inadequate escaping of shell metacharacters within these filenames, which are subsequently used in shell command execution. For successful exploitation, user interaction is required, as the utility must be triggered with the malicious file. This vulnerability poses significant risks to the confidentiality, integrity, and availability of user's data.
References
CVSS V3.1
Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
This issue was discovered by Found by AISLE in partnership with Red Hat.