{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/vendors/rpm/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:rpm:rpm:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7,"id":"CVE-2026-84233"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["rpm"],"_cs_severities":["high"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["RPM"],"content_html":"\u003cp\u003eA security flaw identified as CVE-2026-84233 exists within the rpm utility, specifically affecting how it handles file operations. A local attacker can create a specially crafted .gem file with a filename that embeds RPM macro syntax. When a local user or an automated build/deployment workflow executes the rpmuncompress -x command on the malicious file, the internal command construction logic improperly expands these macros. This expansion leads to the execution of arbitrary commands under the security context of the user or service account initiating the process. This vulnerability poses a significant risk to the integrity and confidentiality of Linux systems that rely on rpm for package handling or automated artifact processing. Defenders should prioritize identifying environments where rpm is used to process untrusted or externally sourced .gem files.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of this vulnerability allows a local attacker to execute commands with the privileges of the invoking account. This can result in full system compromise if the rpmuncompress utility is invoked by privileged users or automated root-level service accounts. The vulnerability affects the rpm utility, a foundational component for software packaging on many Linux distributions.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eInventory all internal build systems and automated workflows that utilize the rpmuncompress utility to process .gem files.\u003c/li\u003e\n\u003cli\u003eImplement strict input validation on filenames before passing them to the rpmuncompress utility in automated pipelines.\u003c/li\u003e\n\u003cli\u003eUpdate the rpm package to the latest version provided by the distribution vendor to remediate CVE-2026-84233.\u003c/li\u003e\n\u003cli\u003eRestrict file system permissions to prevent untrusted local users from placing files in directories monitored by automated build agents.\u003c/li\u003e\n\u003c/ol\u003e\n","date_modified":"2026-09-01T17:06:46Z","date_published":"2026-09-01T17:06:46Z","id":"https://feed.craftedsignal.io/briefs/2026-09-rpm-cve-2026-84233/","summary":"A local command injection vulnerability (CVE-2026-84233) in the rpm utility allows execution of arbitrary commands when rpmuncompress processes maliciously crafted filenames containing RPM macro syntax.","title":"Command Injection in rpm via Crafted .gem Filenames","url":"https://feed.craftedsignal.io/briefs/2026-09-rpm-cve-2026-84233/"}],"language":"en","title":"CraftedSignal Threat Feed - RPM","version":"https://jsonfeed.org/version/1.1"}