CVE-2026-78367
Received
Received - Intake
rpmbuild Macro Injection via Crafted Tarball
Vulnerability report for CVE-2026-78367, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.
Publication date: 2026-08-24
Last updated on: 2026-08-24
Assigner: redhat-SADP
Description
Description
A flaw was found in rpmbuild. When rpmbuild processes a crafted tarball in tarball mode, a specially designed tar member name can lead to macro injection. This vulnerability allows a remote attacker to execute arbitrary code on the system by convincing a user to build a malicious tarball.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| redhat | rpmbuild | * |
| redhat | rpmbuild | From 4.16.1 (inc) |
| redhat | rpmbuild | From 6.0.2 (inc) |
| redhat | rpmbuild | 7 |
| redhat | rpmbuild | 8 |
| redhat | rpmbuild | 9 |
| redhat | rpmbuild | 10 |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-74 | The product constructs all or part of a command, data structure, or record using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify how it is parsed or interpreted when it is sent to a downstream component. |