{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/rpmuncompress/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:rpm:rpmuncompress:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.8,"id":"CVE-2026-84838"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["rpmuncompress"],"_cs_severities":["high"],"_cs_tags":["vulnerability","command-injection","linux"],"_cs_type":"advisory","_cs_vendors":["rpm"],"content_html":"\u003cp\u003eCVE-2026-84838 is a command injection vulnerability residing within the rpmuncompress utility. The flaw exists due to improper sanitization of archive filenames, which allows an attacker to inject arbitrary shell metacharacters into the command execution flow. When a user or an automated script processes a malicious archive file using rpmuncompress, the unescaped filename is passed directly to the underlying shell command string. This leads to the execution of attacker-supplied commands with the privileges of the user running the utility. Defenders should be aware that this vulnerability facilitates local privilege escalation or arbitrary code execution, impacting the confidentiality, integrity, and availability of data accessible by the affected process.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of CVE-2026-84838 allows a local attacker to execute arbitrary commands, potentially resulting in full system compromise for the specific user context in which rpmuncompress is invoked. Automated workflows that process externally sourced archive files are at higher risk.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eMonitor for the execution of rpmuncompress on systems processing external or untrusted archive files.\u003c/li\u003e\n\u003cli\u003eImplement input validation on filenames before passing them to archive extraction utilities in automated workflows.\u003c/li\u003e\n\u003cli\u003eAudit logs for instances where rpmuncompress is invoked with filenames containing shell metacharacters like semicolon (;), pipe (|), or backticks (`).\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-02T17:16:24Z","date_published":"2026-09-02T17:16:24Z","id":"https://feed.craftedsignal.io/briefs/2026-09-rpmuncompress-cmd-injection/","summary":"A command injection vulnerability in rpmuncompress allows local attackers to execute arbitrary code by supplying specially crafted archive filenames containing shell metacharacters.","title":"Command Injection Vulnerability in rpmuncompress","url":"https://feed.craftedsignal.io/briefs/2026-09-rpmuncompress-cmd-injection/"}],"language":"en","title":"CraftedSignal Threat Feed - Rpmuncompress","version":"https://jsonfeed.org/version/1.1"}