<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>RPM (7.0-7.8) - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/products/rpm-7.0-7.8/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Fri, 25 Sep 2026 14:01:04 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/products/rpm-7.0-7.8/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Multiple Arbitrary Code Execution Vulnerabilities in RPM</title><link>https://feed.craftedsignal.io/briefs/2026-09-rpm-vulnerabilities/</link><pubDate>Fri, 25 Sep 2026 14:01:04 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-09-rpm-vulnerabilities/</guid><description>Multiple unpatched vulnerabilities in the RPM package manager allow an unauthenticated attacker to achieve arbitrary code execution on systems processing malicious packages.</description><content:encoded><![CDATA[<p>The German Federal Office for Information Security (BSI) has released an advisory regarding multiple vulnerabilities within the RPM (RPM Package Manager) utility. These flaws are currently unpatched and present a significant risk to Linux distributions relying on RPM for software management. The vulnerabilities are triggered during the handling and installation of specially crafted RPM packages. An attacker capable of delivering a malicious package to a system administrator or automated package management process could exploit these flaws to execute arbitrary code with the privileges of the user or process performing the installation. Given the widespread use of RPM across enterprise Linux environments, this impact is considered critical for systems that frequently ingest third-party or untrusted software repositories.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation allows for complete system compromise, including the installation of persistent backdoors, data exfiltration, or the deployment of ransomware. The scope of impact extends to all Linux distributions utilizing RPM, affecting server, desktop, and containerized environments.</p>
<h2 id="recommendation">Recommendation</h2>
<p>Prioritized actions for security teams:</p>
<ul>
<li>Monitor system logs for unexpected executions of the 'rpm' or 'dnf' binaries, particularly those occurring in automated build pipelines or unusual user contexts.</li>
<li>Implement strict repository validation policies to ensure only signed packages from trusted sources are ingested.</li>
<li>Audit build and deployment pipelines to identify automated processes that automatically pull and install RPM packages from external, non-verified sources.</li>
<li>Restrict local installation of RPM packages to authorized administrators only.</li>
<li>Monitor vendor-specific security mailing lists and repository mirrors for the release of security patches addressing these specific RPM vulnerabilities.</li>
</ul>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category><category>vulnerability</category><category>linux</category><category>rpm</category><category>local-exploitation</category></item></channel></rss>