{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/tags/rpmbuild/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":7,"id":"CVE-2026-78367"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Red Hat Enterprise Linux 7","Red Hat Enterprise Linux 8","Red Hat Enterprise Linux 9","Red Hat Enterprise Linux 10","Red Hat Hardened Images"],"_cs_severities":["high"],"_cs_tags":["vulnerability","rce","rpmbuild","rhel"],"_cs_type":"advisory","_cs_vendors":["Red Hat"],"content_html":"\u003cp\u003eCVE-2026-78367 is a macro injection vulnerability in \u003ccode\u003erpmbuild\u003c/code\u003e, a utility commonly used within Red Hat Enterprise Linux (RHEL) environments to build RPM packages. When \u003ccode\u003erpmbuild\u003c/code\u003e operates in tarball mode and processes a specially crafted tarball, an attacker can leverage malicious tar member names to trigger macro injection. Successful exploitation results in arbitrary code execution on the target system.\u003c/p\u003e\n\u003cp\u003eThe attack requires user interaction, specifically convincing a user to perform an \u003ccode\u003erpmbuild\u003c/code\u003e operation on a malicious archive. Given that \u003ccode\u003erpmbuild\u003c/code\u003e is frequently used by developers, build engineers, and system administrators, the impact is highest in environments where external or untrusted source tarballs are processed during CI/CD or package maintenance workflows. The vulnerability is tracked as CWE-74 (Improper Neutralization of Special Elements in Output Used by a Downstream Component).\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eThe vulnerability carries a CVSS 3.1 score of 7.0. If exploited, an attacker can gain the same level of access as the user running the \u003ccode\u003erpmbuild\u003c/code\u003e command. This can lead to full system compromise, exfiltration of source code or environment credentials, and persistent backdooring of build environments. Targeted sectors include any organization relying on RHEL-based distributions for software development or infrastructure management.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritize patching systems where \u003ccode\u003erpmbuild\u003c/code\u003e is active in automated build pipelines.\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eReview and restrict the use of untrusted source tarballs in automated build environments.\u003c/li\u003e\n\u003cli\u003eApply security patches provided by Red Hat for RHEL 7, 8, 9, and 10 as soon as they are made available via official channels.\u003c/li\u003e\n\u003cli\u003eAudit build logs for suspicious file names or macro characters within tarball member names.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-24T16:03:04Z","date_published":"2026-08-24T16:03:04Z","id":"https://feed.craftedsignal.io/briefs/2026-08-rpmbuild-macro-injection/","summary":"A macro injection vulnerability in rpmbuild allows remote attackers to achieve arbitrary code execution by convincing a user to process a specially crafted tarball.","title":"Macro Injection Vulnerability in rpmbuild (CVE-2026-78367)","url":"https://feed.craftedsignal.io/briefs/2026-08-rpmbuild-macro-injection/"}],"language":"en","title":"CraftedSignal Threat Feed - Rpmbuild","version":"https://jsonfeed.org/version/1.1"}