CVE-2026-95520
Received Received - Intake

Heap-based Buffer Overflow in RPM Package Parsing

Vulnerability report for CVE-2026-95520, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-29

Last updated on: 2026-09-29

Assigner: redhat-SADP

Description

A heap-based buffer overflow flaw was found in rpm. Parsing a symlink entry in an untrusted RPM package whose declared RPMTAG_LONGFILESIZES value is 0xFFFFFFFFFFFFFFFF causes an integer overflow in iterReadArchiveNext() that shrinks a buffer allocation to one byte, after which the payload's independently-controlled cpio filesize field is used to write attacker-controlled data past the end of that allocation. This is reachable via rpm2cpio, rpm2archive, and rpm -qlvp on an untrusted package.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-29
Last Modified
2026-09-29
Generated
2026-09-29
AI Q&A
2026-09-29
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
redhat rpm *
redhat rpm From 0xFFFFFFFFFFFFFFFF (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-787 The product writes data past the end, or before the beginning, of the intended buffer.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is a heap-based buffer overflow in the RPM package manager. When parsing a malicious RPM package with a crafted symlink entry, an integer overflow in the iterReadArchiveNext() function incorrectly allocates a 1-byte buffer. Attacker-controlled data from the package can then overflow this buffer, potentially causing memory corruption or arbitrary code execution.

Detection Guidance

To detect this vulnerability, monitor for suspicious activity when processing RPM packages. Check for untrusted RPM files with RPMTAG_LONGFILESIZES set to 0xFFFFFFFFFFFFFFFF. Use rpm -qlvp on suspicious packages to see if it triggers errors or crashes. Enable AddressSanitizer in rpm builds to detect heap-based buffer overflows during package processing.

Impact Analysis

If you process untrusted RPM packages using commands like rpm2cpio, rpm2archive, or rpm -qlvp, this flaw could allow attackers to execute arbitrary code or crash your system. The attack requires user interaction to process the malicious package but does not need network access.

Compliance Impact

This vulnerability primarily affects integrity and availability of systems processing untrusted RPM packages. While it does not directly handle personal or sensitive data, exploitation could lead to system compromise, potentially violating compliance requirements for secure processing environments under standards like GDPR (data integrity) and HIPAA (system availability and integrity). The risk depends on whether untrusted RPM packages are processed in regulated environments.

Mitigation Strategies

Avoid processing RPM packages from untrusted sources. Verify package integrity and origin before using rpm2cpio, rpm2archive, or rpm -qlvp. Update rpm to the latest patched version once available. Monitor Red Hat advisories for official fixes and apply them promptly.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-95520. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart