CVE-2026-44605

EUVD-2026-53565
A flaw was found in the RPM Package Manager (RPM). A local user could be affected by a heap buffer overflow vulnerability when processing a specially crafted NDB database file. This issue arises from an error in how RPM handles certain calculations during file parsing, leading to an incorrect memory allocation. An attacker could leverage this to cause a denial of service, making the system unavailable.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
5.5 MEDIUM
LOCAL
LOW
NONE
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Awaiting analysis
This vulnerability is currently awaiting analysis.
Base Score
CVSS 3.x
EPSS Score
Percentile: Unknown
Debian logo
Debian Releases
Debian Product
Codename
rpm
bookworm
postponed
bullseye
postponed
forky
vulnerable
sid
vulnerable
trixie
no-dsa
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
rpm
bionic
needs-triage
focal
needs-triage
jammy
needs-triage
noble
needs-triage
questing
ignored
resolute
needs-triage
trusty
needs-triage
Amazon Linux logo
Amazon Linux Releases
Amazon Package
Release
python3-rpm
Amazon Linux 2023
0:4.16.1.3-29.amzn2023.0.7
fixed
python3-rpm-debuginfo
Amazon Linux 2023
0:4.16.1.3-29.amzn2023.0.7
fixed
rpm
Amazon Linux 2023
0:4.16.1.3-29.amzn2023.0.7
fixed
rpm-apidocs
Amazon Linux 2023
0:4.16.1.3-29.amzn2023.0.7
fixed
rpm-build
Amazon Linux 2023
0:4.16.1.3-29.amzn2023.0.7
fixed
rpm-build-debuginfo
Amazon Linux 2023
0:4.16.1.3-29.amzn2023.0.7
fixed
rpm-build-libs
Amazon Linux 2023
0:4.16.1.3-29.amzn2023.0.7
fixed
rpm-build-libs-debuginfo
Amazon Linux 2023
0:4.16.1.3-29.amzn2023.0.7
fixed
rpm-cron
Amazon Linux 2023
0:4.16.1.3-29.amzn2023.0.7
fixed
rpm-debuginfo
Amazon Linux 2023
0:4.16.1.3-29.amzn2023.0.7
fixed
rpm-debugsource
Amazon Linux 2023
0:4.16.1.3-29.amzn2023.0.7
fixed
rpm-devel
Amazon Linux 2023
0:4.16.1.3-29.amzn2023.0.7
fixed
rpm-devel-debuginfo
Amazon Linux 2023
0:4.16.1.3-29.amzn2023.0.7
fixed
rpm-libs
Amazon Linux 2023
0:4.16.1.3-29.amzn2023.0.7
fixed
rpm-libs-debuginfo
Amazon Linux 2023
0:4.16.1.3-29.amzn2023.0.7
fixed
rpm-plugin-audit
Amazon Linux 2023
0:4.16.1.3-29.amzn2023.0.7
fixed
rpm-plugin-audit-debuginfo
Amazon Linux 2023
0:4.16.1.3-29.amzn2023.0.7
fixed
rpm-plugin-fapolicyd
Amazon Linux 2023
0:4.16.1.3-29.amzn2023.0.7
fixed
rpm-plugin-fapolicyd-debuginfo
Amazon Linux 2023
0:4.16.1.3-29.amzn2023.0.7
fixed
rpm-plugin-ima
Amazon Linux 2023
0:4.16.1.3-29.amzn2023.0.7
fixed
rpm-plugin-ima-debuginfo
Amazon Linux 2023
0:4.16.1.3-29.amzn2023.0.7
fixed
rpm-plugin-prioreset
Amazon Linux 2023
0:4.16.1.3-29.amzn2023.0.7
fixed
rpm-plugin-prioreset-debuginfo
Amazon Linux 2023
0:4.16.1.3-29.amzn2023.0.7
fixed
rpm-plugin-selinux
Amazon Linux 2023
0:4.16.1.3-29.amzn2023.0.7
fixed
rpm-plugin-selinux-debuginfo
Amazon Linux 2023
0:4.16.1.3-29.amzn2023.0.7
fixed
rpm-plugin-syslog
Amazon Linux 2023
0:4.16.1.3-29.amzn2023.0.7
fixed
rpm-plugin-syslog-debuginfo
Amazon Linux 2023
0:4.16.1.3-29.amzn2023.0.7
fixed
rpm-plugin-systemd-inhibit
Amazon Linux 2023
0:4.16.1.3-29.amzn2023.0.7
fixed
rpm-plugin-systemd-inhibit-debuginfo
Amazon Linux 2023
0:4.16.1.3-29.amzn2023.0.7
fixed
rpm-sign
Amazon Linux 2023
0:4.16.1.3-29.amzn2023.0.7
fixed
rpm-sign-debuginfo
Amazon Linux 2023
0:4.16.1.3-29.amzn2023.0.7
fixed
rpm-sign-libs
Amazon Linux 2023
0:4.16.1.3-29.amzn2023.0.7
fixed
rpm-sign-libs-debuginfo
Amazon Linux 2023
0:4.16.1.3-29.amzn2023.0.7
fixed