A heap-based buffer overflow flaw was found in rpm. Parsing a symlink entry in an untrusted RPM package whose declared RPMTAG_LONGFILESIZES value is 0xFFFFFFFFFFFFFFFF causes an integer overflow in iterReadArchiveNext() that shrinks a buffer allocation to one byte, after which the payload's independently-controlled cpio filesize field is used to write attacker-controlled data past the end of that allocation. This is reachable via rpm2cpio, rpm2archive, and rpm -qlvp on an untrusted package.

Project Subscriptions

Vendors Products
Enterprise Linux Subscribe
Hummingbird Subscribe
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

To reduce exposure, avoid processing or extracting RPM packages from untrusted sources. Do not use `rpm2cpio`, `rpm2archive`, or `rpm -qlvp` on RPM files whose origin and integrity cannot be verified.

History

Tue, 29 Sep 2026 13:15:00 +0000

Type Values Removed Values Added
Description A heap-based buffer overflow flaw was found in rpm. Parsing a symlink entry in an untrusted RPM package whose declared RPMTAG_LONGFILESIZES value is 0xFFFFFFFFFFFFFFFF causes an integer overflow in iterReadArchiveNext() that shrinks a buffer allocation to one byte, after which the payload's independently-controlled cpio filesize field is used to write attacker-controlled data past the end of that allocation. This is reachable via rpm2cpio, rpm2archive, and rpm -qlvp on an untrusted package.
Title Rpm: rpm: integer overflow in iterreadarchivenext() leads to heap-based buffer overflow when parsing untrusted rpm packages
First Time appeared Redhat
Redhat enterprise Linux
Redhat hummingbird
Weaknesses CWE-787
CPEs cpe:/a:redhat:hummingbird:1
cpe:/o:redhat:enterprise_linux:10
cpe:/o:redhat:enterprise_linux:6
cpe:/o:redhat:enterprise_linux:7
cpe:/o:redhat:enterprise_linux:8
cpe:/o:redhat:enterprise_linux:9
Vendors & Products Redhat
Redhat enterprise Linux
Redhat hummingbird
References
Metrics threat_severity

None

cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H'}

threat_severity

Moderate


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published:

Updated: 2026-09-29T13:19:42.202Z

Reserved: 2026-09-22T08:44:44.967Z

Link: CVE-2026-95520

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-29T12:17:12.650

Modified: 2026-09-29T12:17:12.650

Link: CVE-2026-95520

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-09-29T10:54:13Z

Links: CVE-2026-95520 - Bugzilla

cve-icon OpenCVE Enrichment

No data.

Weaknesses