CVE-2026-103242High· 7.1▾ TwilightA heap-based buffer overflow flaw was found in rpm. RPMTAG_FILESIGNATURES in a crafted, unsigned RPM package's main header is declared with the wrong header type, causing hex2binv() to allocate a one-byte buffer and then write the tag's …
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 39.1 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
A heap-based buffer overflow flaw was found in rpm. RPMTAG_FILESIGNATURES in a crafted, unsigned RPM package's main header is declared with the wrong header type, causing hex2binv() to allocate a one-byte buffer and then write the tag's attacker-controlled, hex-decoded content — of attacker-chosen length — past the end of that allocation. This is reachable via rpm2cpio, rpm2archive, and rpm -qlvp on an untrusted package.
rpm (all versions)rpmrpmrpm (all versions)rpm (all versions)rpm (all versions)Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Avoid processing or extracting RPM packages from untrusted or unsigned sources. Do not run rpm -qlvp, rpm2cpio, or rpm2archive against RPM files whose origin and integrity cannot be verified.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-95520High· 7.1A heap-based buffer overflow flaw was found in rpm
CVE-2026-88386Medium· 5.5libsndfile 1.2.2 contains a misaligned memory access issue in psf_binheader_readf() while parsing WAV fmt chunks
CVE-2026-95521High· 7.8A command injection flaw was found in rpm
CVE-2026-95519High· 7.8A flaw was found in rpm
CVE-2016-15059Critical· 9.8Net::IDN::Punycode versions before 2.301 for Perl allow a heap buffer overflow via unchecked writes past the output buffer in encode_punycode. The XS backend builds the encoded label in the string buffer of the scalar it returns, sized …
CVE-2026-18495Medium· 6.1A flaw was found in libtiff