Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-44604— Rpm: command injection in rpmuncompress dountar() via unescaped archive top-level directory name in popen() shell command

Quick assessment

Affected
Red Hat Red Hat Hardened Images
Exploitation
Public or AI PoC available; prioritize validation
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

rpm是rpm组织的一个强大的命令行驱动的软件包管理工具,用来安装、卸载、校验、查询和更新 Linux 系统上的软件包。 rpm存在操作系统命令注入漏洞,该漏洞源于rpmuncompress工具在提取特定存档格式到指定目标目录时,将存档的顶级文件夹名称插入shell命令而未进行适当清理,特制存档中的shell元字符可导致执行任意命令。

CVSS 7.0 · High EPSS 0.92% · P59

Possible ATT&CK Techniques 1 AI

T1059 · Command and Scripting Interpreter

Affected Version Matrix 6

VendorProduct Version RangeStatus
Red Hat Red Hat Enterprise Linux 10 any unaffected
Red Hat Red Hat Enterprise Linux 6 any unaffected
Red Hat Red Hat Enterprise Linux 7 any unaffected
Red Hat Red Hat Enterprise Linux 8 any unaffected
Red Hat Red Hat Enterprise Linux 9 any unaffected
Red Hat Red Hat Hardened Images 6.0.1-6.1.hum1< * unaffected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-44604

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Rpm: command injection in rpmuncompress dountar() via unescaped archive top-level directory name in popen() shell command
Source: CVE Program / CVE List V5
Vulnerability Description
A command injection vulnerability was discovered in the `rpmuncompress` utility of RPM. When extracting certain archive formats (ZIP, 7z, GEM) to a specified destination directory, the tool inserts the archive's top-level folder name into a shell command without properly sanitizing it. A specially crafted archive containing shell metacharacters in its folder name can execute arbitrary commands as the user running the extraction.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
OS命令中使用的特殊元素转义处理不恰当(OS命令注入)
Source: CVE Program / CVE List V5
Vulnerability Title
rpm 操作系统命令注入漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
rpm是rpm组织的一个强大的命令行驱动的软件包管理工具,用来安装、卸载、校验、查询和更新 Linux 系统上的软件包。 rpm存在操作系统命令注入漏洞,该漏洞源于rpmuncompress工具在提取特定存档格式到指定目标目录时,将存档的顶级文件夹名称插入shell命令而未进行适当清理,特制存档中的shell元字符可导致执行任意命令。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

Vendor Product Affected Versions CPE Subscribe
Red Hat Red Hat Hardened Images 6.0.1-6.1.hum1 ~ * cpe:/a:redhat:hummingbird:1
Red Hat Red Hat Enterprise Linux 10 - cpe:/o:redhat:enterprise_linux:10
Red Hat Red Hat Enterprise Linux 6 - cpe:/o:redhat:enterprise_linux:6
Red Hat Red Hat Enterprise Linux 7 - cpe:/o:redhat:enterprise_linux:7
Red Hat Red Hat Enterprise Linux 8 - cpe:/o:redhat:enterprise_linux:8
Red Hat Red Hat Enterprise Linux 9 - cpe:/o:redhat:enterprise_linux:9

II. Public POCs for CVE-2026-44604

# POC Description Source Link Shenlong Link
AI-Generated POC Premium
default-local-qwen3.6 · 10869 chars
Pro+ exclusive includes:
Vulnerability reproduction recording (real sandbox build + trigger, exclusive)
In-depth vulnerability mechanism
Trigger conditions & impact
Full executable POC code
Exploit chain & mitigation
POC zip download
100+ AI POC generations per month

III. Intelligence Information for CVE-2026-44604

请登录查看更多情报信息。

Vendor Advisories for CVE-2026-44604 (1)

Other References for CVE-2026-44604 (2)

Same Patch Batch · Red Hat · 2026-05-28 · 14 CVEs total

CVE-2026-4408 9.0 CRITICAL Samba: remote code execution in samr
CVE-2026-9804 7.7 HIGH Kubevirt: kubevirt: vmexport directory symlink escape enables exporter pod file read
CVE-2026-9795 7.3 HIGH Keycloak: keycloak: privilege escalation via improper scope mapping enforcement
CVE-2026-9802 6.8 MEDIUM Keycloak: keycloak: unauthorized account access via replayed refresh tokens after cluster
CVE-2026-9792 6.5 MEDIUM Keycloak: keycloak: security restriction bypass allows unauthorized ropc token acquisition
CVE-2026-9796 6.5 MEDIUM Keycloak: keycloak: privilege escalation via time-of-check to time-of-use (toctou) vulnera
CVE-2026-9793 5.9 MEDIUM Keycloak: keycloak: security policy bypass in jwe-encrypted request object processing
CVE-2026-9794 5.3 MEDIUM Keycloak: keycloak: information disclosure via saml ecp endpoint
CVE-2026-9803 5.3 MEDIUM Keycloak: keycloak: denial of service via malformed authorization header
CVE-2026-9801 4.9 MEDIUM Keycloak: keycloak: denial of service via malformed ldap password policy response
CVE-2026-9791 4.3 MEDIUM Keycloak-rhel9: organization data leak after feature disabled in keycloak
CVE-2026-9798 4.3 MEDIUM Keycloak: keycloak: brute-force protection bypass in ciba flow
CVE-2026-10028 4.3 MEDIUM Glib-networking: infinite loop in glib-networking gnutls backend allows remote denial of s

IV. Related Vulnerabilities

V. Comments for CVE-2026-44604

No comments yet


Leave a comment