Product
Heap-Based Buffer Overflow in RPM Package Manager (CVE-2026-95520)
1 TTP 1 CVEA heap-based buffer overflow in the RPM Package Manager allows for out-of-bounds writes and potential code execution when processing maliciously crafted RPM files containing specific symlink entries.
Multiple Arbitrary Code Execution Vulnerabilities in RPM
2 TTPs 1 CVEMultiple unpatched vulnerabilities in the RPM package manager allow an unauthenticated attacker to achieve arbitrary code execution on systems processing malicious packages.
Command Injection in RPM Package Manager
1 TTP 1 CVEA command injection vulnerability (CVE-2026-95521) in the rpm package manager allows arbitrary command execution when processing maliciously crafted source RPM files containing %() macro constructs.
Command Injection in rpm via Crafted .gem Filenames
1 TTP 1 CVEA local command injection vulnerability (CVE-2026-84233) in the rpm utility allows execution of arbitrary commands when rpmuncompress processes maliciously crafted filenames containing RPM macro syntax.
Arbitrary Code Execution Vulnerability in RPM Package Manager
1 TTP 1 CVEA local vulnerability in the RPM package management utility allows an attacker to execute arbitrary code with the privileges of the user executing the command.
CVE-2026-44604: RPM rpmuncompress Command Injection Vulnerability
2 rules 1 TTP 1 CVEA command injection vulnerability (CVE-2026-44604) exists in the `rpmuncompress` utility of RPM; when extracting specially crafted ZIP, 7z, or GEM archives, an attacker can inject shell commands via a malicious top-level folder name, leading to arbitrary code execution as the user running the extraction.