RPM是Rpm团队开源的一款操作系统软件包管理工具。 RPM存在输入验证错误漏洞,该漏洞源于在tarball模式下处理特制tarball时,特制的tar成员名称可能导致宏注入,远程攻击者通过诱骗用户构建恶意tarball可在系统上执行任意代码。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Red Hat | Red Hat Enterprise Linux 10 | any |
affected |
| Red Hat | Red Hat Enterprise Linux 6 | any |
unknown |
| Red Hat | Red Hat Enterprise Linux 7 | any |
affected |
| Red Hat | Red Hat Enterprise Linux 8 | any |
affected |
| Red Hat | Red Hat Enterprise Linux 9 | any |
affected |
| Red Hat | Red Hat Hardened Images | any |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Red Hat | Red Hat Enterprise Linux 10 | - |
cpe:/o:redhat:enterprise_linux:10
|
|
| Red Hat | Red Hat Enterprise Linux 6 | - |
cpe:/o:redhat:enterprise_linux:6
|
|
| Red Hat | Red Hat Enterprise Linux 7 | - |
cpe:/o:redhat:enterprise_linux:7
|
|
| Red Hat | Red Hat Enterprise Linux 8 | - |
cpe:/o:redhat:enterprise_linux:8
|
|
| Red Hat | Red Hat Enterprise Linux 9 | - |
cpe:/o:redhat:enterprise_linux:9
|
|
| Red Hat | Red Hat Hardened Images | - |
cpe:/a:redhat:hummingbird:1
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
| CVE-2026-71366 | 7.7 HIGH | Awx: notification backends allow ssrf and credential leakage |
| CVE-2026-71364 | 7.2 HIGH | Awx: project archive extraction allows path traversal file writes |
| CVE-2026-19685 | 7.1 HIGH | Networkmanager: networkmanager: 802-1x ca-path and phase2-ca-path bypass private_user rest |
| CVE-2026-78323 | 6.5 MEDIUM | Jss: jss: jsstrustmanager does not verify nss trust flags on ca certificates |
No comments yet