CVE-2026-78367

EUVD-2026-64885
A vulnerability was found in RPM's rpmbuild tarball processing. When processing a crafted source archive, the getTarSpec() function in tools/rpmbuild.cc passes an attacker-controlled tar archive member name to rpmExpand() as part of a %{basename:...} macro expression. A specially crafted .spec member name can therefore inject RPM macros, including Lua expressions, resulting in arbitrary code execution with the privileges of the user running rpmbuild. This can be exploited when a victim or automated build system processes an attacker-controlled source tarball using rpmbuild tarball mode (such as -ts, -ta, or -tb).
Code Injection
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
7 HIGH
LOCAL
HIGH
NONE
CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
Awaiting analysis
This vulnerability is currently awaiting analysis.
Base Score
CVSS 3.x
EPSS Score
Percentile: 8.53%
Debian logo
Debian Releases
Debian Product
Codename
rpm
bookworm
postponed
forky
vulnerable
sid
vulnerable
trixie
no-dsa
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
rpm
bionic
needs-triage
focal
needs-triage
jammy
needs-triage
noble
needs-triage
resolute
needs-triage
trusty
needs-triage
xenial
needs-triage
Amazon Linux logo
Amazon Linux Releases
Amazon Package
Release
python3-rpm
Amazon Linux 2023
0:4.16.1.3-29.amzn2023.0.8
fixed
python3-rpm-debuginfo
Amazon Linux 2023
0:4.16.1.3-29.amzn2023.0.8
fixed
rpm
Amazon Linux 2023
0:4.16.1.3-29.amzn2023.0.8
fixed
rpm-apidocs
Amazon Linux 2023
0:4.16.1.3-29.amzn2023.0.8
fixed
rpm-build
Amazon Linux 2023
0:4.16.1.3-29.amzn2023.0.8
fixed
rpm-build-debuginfo
Amazon Linux 2023
0:4.16.1.3-29.amzn2023.0.8
fixed
rpm-build-libs
Amazon Linux 2023
0:4.16.1.3-29.amzn2023.0.8
fixed
rpm-build-libs-debuginfo
Amazon Linux 2023
0:4.16.1.3-29.amzn2023.0.8
fixed
rpm-cron
Amazon Linux 2023
0:4.16.1.3-29.amzn2023.0.8
fixed
rpm-debuginfo
Amazon Linux 2023
0:4.16.1.3-29.amzn2023.0.8
fixed
rpm-debugsource
Amazon Linux 2023
0:4.16.1.3-29.amzn2023.0.8
fixed
rpm-devel
Amazon Linux 2023
0:4.16.1.3-29.amzn2023.0.8
fixed
rpm-devel-debuginfo
Amazon Linux 2023
0:4.16.1.3-29.amzn2023.0.8
fixed
rpm-libs
Amazon Linux 2023
0:4.16.1.3-29.amzn2023.0.8
fixed
rpm-libs-debuginfo
Amazon Linux 2023
0:4.16.1.3-29.amzn2023.0.8
fixed
rpm-plugin-audit
Amazon Linux 2023
0:4.16.1.3-29.amzn2023.0.8
fixed
rpm-plugin-audit-debuginfo
Amazon Linux 2023
0:4.16.1.3-29.amzn2023.0.8
fixed
rpm-plugin-fapolicyd
Amazon Linux 2023
0:4.16.1.3-29.amzn2023.0.8
fixed
rpm-plugin-fapolicyd-debuginfo
Amazon Linux 2023
0:4.16.1.3-29.amzn2023.0.8
fixed
rpm-plugin-ima
Amazon Linux 2023
0:4.16.1.3-29.amzn2023.0.8
fixed
rpm-plugin-ima-debuginfo
Amazon Linux 2023
0:4.16.1.3-29.amzn2023.0.8
fixed
rpm-plugin-prioreset
Amazon Linux 2023
0:4.16.1.3-29.amzn2023.0.8
fixed
rpm-plugin-prioreset-debuginfo
Amazon Linux 2023
0:4.16.1.3-29.amzn2023.0.8
fixed
rpm-plugin-selinux
Amazon Linux 2023
0:4.16.1.3-29.amzn2023.0.8
fixed
rpm-plugin-selinux-debuginfo
Amazon Linux 2023
0:4.16.1.3-29.amzn2023.0.8
fixed
rpm-plugin-syslog
Amazon Linux 2023
0:4.16.1.3-29.amzn2023.0.8
fixed
rpm-plugin-syslog-debuginfo
Amazon Linux 2023
0:4.16.1.3-29.amzn2023.0.8
fixed
rpm-plugin-systemd-inhibit
Amazon Linux 2023
0:4.16.1.3-29.amzn2023.0.8
fixed
rpm-plugin-systemd-inhibit-debuginfo
Amazon Linux 2023
0:4.16.1.3-29.amzn2023.0.8
fixed
rpm-sign
Amazon Linux 2023
0:4.16.1.3-29.amzn2023.0.8
fixed
rpm-sign-debuginfo
Amazon Linux 2023
0:4.16.1.3-29.amzn2023.0.8
fixed
rpm-sign-libs
Amazon Linux 2023
0:4.16.1.3-29.amzn2023.0.8
fixed
rpm-sign-libs-debuginfo
Amazon Linux 2023
0:4.16.1.3-29.amzn2023.0.8
fixed