Skip to content
Threat Feed
high advisory

Heap-Based Buffer Overflow in RPM Package Manager (CVE-2026-95520)

A heap-based buffer overflow in the RPM Package Manager allows for out-of-bounds writes and potential code execution when processing maliciously crafted RPM files containing specific symlink entries.

CVE search metadata

CVE search record: CVE-2026-95520. Severity: high. CVSS: 7.1. KEV: no. Product: rpm. Brief: Heap-Based Buffer Overflow in RPM Package Manager (CVE-2026-95520). Brief link: https://feed.craftedsignal.io/briefs/2026-09-rpm-heap-overflow/

CVE-2026-95520 is a critical heap-based buffer overflow vulnerability identified in the RPM Package Manager. The vulnerability resides in the iterReadArchiveNext() function, which is responsible for processing archive entries within an RPM package. An attacker can exploit this by providing a specially crafted RPM file containing a symlink entry where the RPMTAG_LONGFILESIZES value is set to 0xFFFFFFFFFFFFFFFF. This specific value triggers an integer overflow, causing the allocation of an undersized buffer (one byte). Subsequent processing of the cpio filesize field allows the attacker to write data beyond the boundary of this buffer. This vulnerability is reachable through common RPM inspection and extraction utilities, including rpm2cpio, rpm2archive, and the rpm -qlvp command. Successfully exploiting this flaw could lead to arbitrary code execution on systems that process untrusted RPM packages.

Impact

Successful exploitation of CVE-2026-95520 allows an attacker to execute arbitrary code with the privileges of the user running the RPM inspection or extraction tools. This poses a significant risk to systems that routinely process third-party or untrusted RPM packages, such as build servers, repository mirrors, or security analysis environments. The ability to trigger this via basic tools like rpm -qlvp significantly increases the attack surface for local users and automated systems alike.

Recommendation

Prioritize the identification of systems that utilize the RPM Package Manager tools to inspect or extract files from external sources. Monitor environments for the execution of rpm, rpm2cpio, and rpm2archive against files originating from untrusted locations. Patch the RPM Package Manager as soon as an updated version is released by the distribution maintainers to address this heap overflow vulnerability.


Immediate actions

Identify systems running RPM utilities on untrusted packages and restrict access to these tools where possible.

Security Operations 48h

Threat Hunt

Monitor execution of rpm, rpm2cpio, or rpm2archive on files downloaded from external repositories.

T1203 medium medium confidence hunt now

Data: Process creation logs with command line arguments

Mitigations

Upgrade rpm to the version containing the patch for CVE-2026-95520.

immediate IT Operations

CVE-2026-95520