CVE-2026-44604
EUVD-2026-3272628.05.2026, 08:16
A command injection vulnerability was discovered in the `rpmuncompress` utility of RPM. When extracting certain archive formats (ZIP, 7z, GEM) to a specified destination directory, the tool inserts the archive's top-level folder name into a shell command without properly sanitizing it. A specially crafted archive containing shell metacharacters in its folder name can execute arbitrary commands as the user running the extraction.
Awaiting analysis
This vulnerability is currently awaiting analysis.
Debian Releases
Ubuntu Releases