Product
low
advisory
Arbitrary Code Execution Vulnerability in RPM Package Manager
1 TTP 1 CVEA local vulnerability in the RPM package management utility allows an attacker to execute arbitrary code with the privileges of the user executing the command.
RPM
vulnerability
linux
code-execution
1t
1c
high
advisory
CVE-2026-44604: RPM rpmuncompress Command Injection Vulnerability
2 rules 1 TTP 1 CVEA command injection vulnerability (CVE-2026-44604) exists in the `rpmuncompress` utility of RPM; when extracting specially crafted ZIP, 7z, or GEM archives, an attacker can inject shell commands via a malicious top-level folder name, leading to arbitrary code execution as the user running the extraction.
RPM
command-injection
CVE-2026-44604
archive-extraction
linux
2r
1t
1c