{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/vendors/rpm-package-manager/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:rpm_package_manager:rpm:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.1,"id":"CVE-2026-95520"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["rpm"],"_cs_severities":["high"],"_cs_tags":["vulnerability","remote-code-execution","rpm","linux"],"_cs_type":"advisory","_cs_vendors":["RPM Package Manager"],"content_html":"\u003cp\u003eCVE-2026-95520 is a critical heap-based buffer overflow vulnerability identified in the RPM Package Manager. The vulnerability resides in the iterReadArchiveNext() function, which is responsible for processing archive entries within an RPM package. An attacker can exploit this by providing a specially crafted RPM file containing a symlink entry where the RPMTAG_LONGFILESIZES value is set to 0xFFFFFFFFFFFFFFFF. This specific value triggers an integer overflow, causing the allocation of an undersized buffer (one byte). Subsequent processing of the cpio filesize field allows the attacker to write data beyond the boundary of this buffer. This vulnerability is reachable through common RPM inspection and extraction utilities, including rpm2cpio, rpm2archive, and the rpm -qlvp command. Successfully exploiting this flaw could lead to arbitrary code execution on systems that process untrusted RPM packages.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of CVE-2026-95520 allows an attacker to execute arbitrary code with the privileges of the user running the RPM inspection or extraction tools. This poses a significant risk to systems that routinely process third-party or untrusted RPM packages, such as build servers, repository mirrors, or security analysis environments. The ability to trigger this via basic tools like rpm -qlvp significantly increases the attack surface for local users and automated systems alike.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritize the identification of systems that utilize the RPM Package Manager tools to inspect or extract files from external sources. Monitor environments for the execution of rpm, rpm2cpio, and rpm2archive against files originating from untrusted locations. Patch the RPM Package Manager as soon as an updated version is released by the distribution maintainers to address this heap overflow vulnerability.\u003c/p\u003e\n","date_modified":"2026-09-29T12:27:18Z","date_published":"2026-09-29T12:27:18Z","id":"https://feed.craftedsignal.io/briefs/2026-09-rpm-heap-overflow/","summary":"A heap-based buffer overflow in the RPM Package Manager allows for out-of-bounds writes and potential code execution when processing maliciously crafted RPM files containing specific symlink entries.","title":"Heap-Based Buffer Overflow in RPM Package Manager (CVE-2026-95520)","url":"https://feed.craftedsignal.io/briefs/2026-09-rpm-heap-overflow/"}],"language":"en","title":"CraftedSignal Threat Feed - RPM Package Manager","version":"https://jsonfeed.org/version/1.1"}