Project Subscriptions
No advisories yet.
Solution
No solution given by the vendor.
Workaround
Avoid processing or extracting RPM packages from untrusted or unsigned sources. Do not run rpm -qlvp, rpm2cpio, or rpm2archive against RPM files whose origin and integrity cannot be verified.
Wed, 30 Sep 2026 12:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A heap-based buffer overflow flaw was found in rpm. RPMTAG_FILESIGNATURES in a crafted, unsigned RPM package's main header is declared with the wrong header type, causing hex2binv() to allocate a one-byte buffer and then write the tag's attacker-controlled, hex-decoded content — of attacker-chosen length — past the end of that allocation. This is reachable via rpm2cpio, rpm2archive, and rpm -qlvp on an untrusted package. | |
| Title | Rpm: heap-based buffer overflow write in hex2binv() via a mistyped rpmtag_filesignatures header tag | |
| First Time appeared |
Redhat
Redhat enterprise Linux Redhat hummingbird |
|
| Weaknesses | CWE-122 | |
| CPEs | cpe:/a:redhat:hummingbird:1 cpe:/o:redhat:enterprise_linux:10 cpe:/o:redhat:enterprise_linux:6 cpe:/o:redhat:enterprise_linux:7 cpe:/o:redhat:enterprise_linux:8 cpe:/o:redhat:enterprise_linux:9 |
|
| Vendors & Products |
Redhat
Redhat enterprise Linux Redhat hummingbird |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2026-09-30T11:50:32.039Z
Reserved: 2026-09-30T10:39:52.447Z
Link: CVE-2026-103242
No data.
Status : Received
Published: 2026-09-30T12:17:12.653
Modified: 2026-09-30T12:17:12.653
Link: CVE-2026-103242
No data.
OpenCVE Enrichment
Updated: 2026-09-30T13:30:17Z