<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Cpe:2.3:a:rpm_package_manager:rpm:*:*:*:*:*:*:*:* - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/cpes/cpe2.3arpm_package_managerrpm/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Tue, 29 Sep 2026 12:27:18 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/cpes/cpe2.3arpm_package_managerrpm/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Heap-Based Buffer Overflow in RPM Package Manager (CVE-2026-95520)</title><link>https://feed.craftedsignal.io/briefs/2026-09-rpm-heap-overflow/</link><pubDate>Tue, 29 Sep 2026 12:27:18 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-09-rpm-heap-overflow/</guid><description>A heap-based buffer overflow in the RPM Package Manager allows for out-of-bounds writes and potential code execution when processing maliciously crafted RPM files containing specific symlink entries.</description><content:encoded><![CDATA[<p>CVE-2026-95520 is a critical heap-based buffer overflow vulnerability identified in the RPM Package Manager. The vulnerability resides in the iterReadArchiveNext() function, which is responsible for processing archive entries within an RPM package. An attacker can exploit this by providing a specially crafted RPM file containing a symlink entry where the RPMTAG_LONGFILESIZES value is set to 0xFFFFFFFFFFFFFFFF. This specific value triggers an integer overflow, causing the allocation of an undersized buffer (one byte). Subsequent processing of the cpio filesize field allows the attacker to write data beyond the boundary of this buffer. This vulnerability is reachable through common RPM inspection and extraction utilities, including rpm2cpio, rpm2archive, and the rpm -qlvp command. Successfully exploiting this flaw could lead to arbitrary code execution on systems that process untrusted RPM packages.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation of CVE-2026-95520 allows an attacker to execute arbitrary code with the privileges of the user running the RPM inspection or extraction tools. This poses a significant risk to systems that routinely process third-party or untrusted RPM packages, such as build servers, repository mirrors, or security analysis environments. The ability to trigger this via basic tools like rpm -qlvp significantly increases the attack surface for local users and automated systems alike.</p>
<h2 id="recommendation">Recommendation</h2>
<p>Prioritize the identification of systems that utilize the RPM Package Manager tools to inspect or extract files from external sources. Monitor environments for the execution of rpm, rpm2cpio, and rpm2archive against files originating from untrusted locations. Patch the RPM Package Manager as soon as an updated version is released by the distribution maintainers to address this heap overflow vulnerability.</p>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category><category>vulnerability</category><category>remote-code-execution</category><category>rpm</category><category>linux</category></item></channel></rss>