{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/rpm-7.0-7.8/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:rpm:rpm:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.1,"id":"CVE-2026-103242"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["RPM","RPM (7.0-7.8)"],"_cs_severities":["high"],"_cs_tags":["vulnerability","linux","rpm","local-exploitation"],"_cs_type":"advisory","_cs_vendors":["RPM"],"content_html":"\u003cp\u003eThe German Federal Office for Information Security (BSI) has released an advisory regarding multiple vulnerabilities within the RPM (RPM Package Manager) utility. These flaws are currently unpatched and present a significant risk to Linux distributions relying on RPM for software management. The vulnerabilities are triggered during the handling and installation of specially crafted RPM packages. An attacker capable of delivering a malicious package to a system administrator or automated package management process could exploit these flaws to execute arbitrary code with the privileges of the user or process performing the installation. Given the widespread use of RPM across enterprise Linux environments, this impact is considered critical for systems that frequently ingest third-party or untrusted software repositories.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows for complete system compromise, including the installation of persistent backdoors, data exfiltration, or the deployment of ransomware. The scope of impact extends to all Linux distributions utilizing RPM, affecting server, desktop, and containerized environments.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritized actions for security teams:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eMonitor system logs for unexpected executions of the 'rpm' or 'dnf' binaries, particularly those occurring in automated build pipelines or unusual user contexts.\u003c/li\u003e\n\u003cli\u003eImplement strict repository validation policies to ensure only signed packages from trusted sources are ingested.\u003c/li\u003e\n\u003cli\u003eAudit build and deployment pipelines to identify automated processes that automatically pull and install RPM packages from external, non-verified sources.\u003c/li\u003e\n\u003cli\u003eRestrict local installation of RPM packages to authorized administrators only.\u003c/li\u003e\n\u003cli\u003eMonitor vendor-specific security mailing lists and repository mirrors for the release of security patches addressing these specific RPM vulnerabilities.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-10-01T14:17:49Z","date_published":"2026-09-25T14:01:04Z","id":"https://feed.craftedsignal.io/briefs/2026-09-rpm-vulnerabilities/","summary":"Multiple unpatched vulnerabilities in the RPM package manager allow an unauthenticated attacker to achieve arbitrary code execution on systems processing malicious packages.","title":"Multiple Arbitrary Code Execution Vulnerabilities in RPM","url":"https://feed.craftedsignal.io/briefs/2026-09-rpm-vulnerabilities/"}],"language":"en","title":"CraftedSignal Threat Feed - RPM (7.0-7.8)","version":"https://jsonfeed.org/version/1.1"}