在 rpm 中发现了一个基于堆栈的缓冲区溢出漏洞。当解析一个不可信 RPM 包中的符号链接条目时,若该包声明的 RPMTAG_LONGFILESIZES 值为 0xFFFFFFFFFFFFFFFF,则会导致 iterReadArchiveNext() 函数中发生整数溢出,使分配的缓冲区大小被缩小为仅 1 字节。随后,攻击者控制的 cpio 文件系统中的文件大小字段被用于写入数据,从而超出该缓冲区边界。此漏洞可通过对不可信包执行 rpm2cpio、rpm2archive 或 rpm -qlvp 命令来触发。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Red Hat | Red Hat Enterprise Linux 10 | - |
cpe:/o:redhat:enterprise_linux:10
|
|
| Red Hat | Red Hat Enterprise Linux 6 | - |
cpe:/o:redhat:enterprise_linux:6
|
|
| Red Hat | Red Hat Enterprise Linux 7 | - |
cpe:/o:redhat:enterprise_linux:7
|
|
| Red Hat | Red Hat Enterprise Linux 8 | - |
cpe:/o:redhat:enterprise_linux:8
|
|
| Red Hat | Red Hat Enterprise Linux 9 | - |
cpe:/o:redhat:enterprise_linux:9
|
|
| Red Hat | Red Hat Hardened Images | - |
cpe:/a:redhat:hummingbird:1
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-97024 | 7.1 HIGH | Flatpak: flatpak: arbitrary write in root context via path traversal in deploy directory f |
| CVE-2026-97029 | 5.7 MEDIUM | Flatpak: flatpak: sandboxed app can signal unsandboxed processes in the same process group |
| CVE-2026-102473 | 5.5 MEDIUM | Dash: dash: super-polynomial backtracking in pmatch when libc fnmatch is disabled |
| CVE-2026-102474 | 4.0 MEDIUM | Dash: dash: heap out-of-bounds write in conv_escape via undersized unicode escape reservat |
No comments yet