Command Injection Vulnerability in rpmuncompress Affects Red Hat Products
CVE-2026-84838

7.8HIGH

What is CVE-2026-84838?

A vulnerability exists in the rpmuncompress utility that allows local attackers to execute arbitrary commands via crafted archive filenames. The flaw arises from inadequate escaping of shell metacharacters within these filenames, which are subsequently used in shell command execution. For successful exploitation, user interaction is required, as the utility must be triggered with the malicious file. This vulnerability poses significant risks to the confidentiality, integrity, and availability of user's data.

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

This issue was discovered by Found by AISLE in partnership with Red Hat.
.