Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-95520— Rpm: rpm: integer overflow in iterreadarchivenext() leads to heap-based buffer overflow when parsing untrusted rpm packages

Quick assessment

Affected
Red Hat Red Hat Enterprise Linux 10
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

在 rpm 中发现了一个基于堆栈的缓冲区溢出漏洞。当解析一个不可信 RPM 包中的符号链接条目时,若该包声明的 RPMTAG_LONGFILESIZES 值为 0xFFFFFFFFFFFFFFFF,则会导致 iterReadArchiveNext() 函数中发生整数溢出,使分配的缓冲区大小被缩小为仅 1 字节。随后,攻击者控制的 cpio 文件系统中的文件大小字段被用于写入数据,从而超出该缓冲区边界。此漏洞可通过对不可信包执行 rpm2cpio、rpm2archive 或 rpm -qlvp 命令来触发。

CVSS 7.1 · High
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-95520

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Rpm: rpm: integer overflow in iterreadarchivenext() leads to heap-based buffer overflow when parsing untrusted rpm packages
Source: CVE Program / CVE List V5
Vulnerability Description
A heap-based buffer overflow flaw was found in rpm. Parsing a symlink entry in an untrusted RPM package whose declared RPMTAG_LONGFILESIZES value is 0xFFFFFFFFFFFFFFFF causes an integer overflow in iterReadArchiveNext() that shrinks a buffer allocation to one byte, after which the payload's independently-controlled cpio filesize field is used to write attacker-controlled data past the end of that allocation. This is reachable via rpm2cpio, rpm2archive, and rpm -qlvp on an untrusted package.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
跨界内存写
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
Red Hat Red Hat Enterprise Linux 10 - cpe:/o:redhat:enterprise_linux:10
Red Hat Red Hat Enterprise Linux 6 - cpe:/o:redhat:enterprise_linux:6
Red Hat Red Hat Enterprise Linux 7 - cpe:/o:redhat:enterprise_linux:7
Red Hat Red Hat Enterprise Linux 8 - cpe:/o:redhat:enterprise_linux:8
Red Hat Red Hat Enterprise Linux 9 - cpe:/o:redhat:enterprise_linux:9
Red Hat Red Hat Hardened Images - cpe:/a:redhat:hummingbird:1

II. Public POCs for CVE-2026-95520

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-95520

请登录查看更多情报信息。

Other References for CVE-2026-95520 (2)

Same Patch Batch · Red Hat · 2026-09-29 · 5 CVEs total

CVE-2026-97024 7.1 HIGH Flatpak: flatpak: arbitrary write in root context via path traversal in deploy directory f
CVE-2026-97029 5.7 MEDIUM Flatpak: flatpak: sandboxed app can signal unsandboxed processes in the same process group
CVE-2026-102473 5.5 MEDIUM Dash: dash: super-polynomial backtracking in pmatch when libc fnmatch is disabled
CVE-2026-102474 4.0 MEDIUM Dash: dash: heap out-of-bounds write in conv_escape via undersized unicode escape reservat

IV. Related Vulnerabilities

V. Comments for CVE-2026-95520

No comments yet


Leave a comment