在 rpm 中发现了一个漏洞。攻击者可以构造一个恶意的清单文件(manifest file),当用户使用 或类似的清单处理流程处理该文件时,会导致任意代码执行。该问题的根源在于:清单条目在打开之前会被意外地进行宏展开,从而使得嵌入的 shell 命令得以在 rpm 进程的权限上下文中执行。成功利用此漏洞可能导致受影响账户的机密性、完整性和可用性遭到完全破坏。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Red Hat | Red Hat Enterprise Linux 10 | - |
cpe:/o:redhat:enterprise_linux:10
|
|
| Red Hat | Red Hat Enterprise Linux 6 | - |
cpe:/o:redhat:enterprise_linux:6
|
|
| Red Hat | Red Hat Enterprise Linux 7 | - |
cpe:/o:redhat:enterprise_linux:7
|
|
| Red Hat | Red Hat Enterprise Linux 8 | - |
cpe:/o:redhat:enterprise_linux:8
|
|
| Red Hat | Red Hat Enterprise Linux 9 | - |
cpe:/o:redhat:enterprise_linux:9
|
|
| Red Hat | Red Hat Hardened Images | - |
cpe:/a:redhat:hummingbird:1
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-90959 | 8.1 HIGH | Pulpcore: pulpcore: file:// scheme allowlist bypass in content upload file_url field enabl |
| CVE-2026-95521 | 7.8 HIGH | Rpm: rpm: shell command injection via macro expansion of source/spec file basenames when i |
| CVE-2026-97185 | 7.8 HIGH | Gimp: gimp: out-of-bounds write in gimpressionist plugin via crafted preset file |
| CVE-2026-94416 | 6.8 MEDIUM | Aap-gateway: aap-gateway: authorization bypass via workload identity token forgery |
| CVE-2026-97177 | 6.6 MEDIUM | Keycloak-services: keycloak-services: generic user update bypasses denied reset-password p |
| CVE-2026-97311 | 4.3 MEDIUM | Keycloak-services: keycloak-services: admin rest api role-groups endpoint discloses groups |
| CVE-2026-97176 | 4.2 MEDIUM | Keycloak-services: keycloak-services: essential acr requirement silently bypassed via cook |
No comments yet