Skip to content
Red HatCVE-2026-103242

Red Hat rpm. RPMTAG_FILESIGNATURES: heap buffer overflow

High7.1CVE-2026-103242 · Published Sep 30, 2026

A heap-based buffer overflow flaw was found in rpm. RPMTAG_FILESIGNATURES in a crafted, unsigned RPM package's main header is declared with the wrong header type, causing hex2binv() to allocate a one-byte buffer and then write the tag's attacker-controlled, hex-decoded content — of attacker-chosen length — past the end of that allocation. This is reachable via rpm2cpio, rpm2archive, and rpm -qlvp on an untrusted package.

Red Hat advisory

Affected versions

PackageAffectedFixed in
Red Hat Enterprise Linux 10
Product
all versionsNo fix yet
Red Hat Enterprise Linux 6
Product
all versionsNo fix yet
Red Hat Enterprise Linux 7
Product
all versionsNo fix yet
Red Hat Enterprise Linux 8
Product
all versionsNo fix yet
Red Hat Enterprise Linux 9
Product
all versionsNo fix yet
Red Hat Hardened Images
Product
all versionsNo fix yet
Details and references

More Red Hat advisories

All Red Hat
Advisory
Red Hat Enterprise Linux: request smuggling
Medium5.3Sep 30
Assisted Installer for Red Hat OpenShift Container Platform : path traversal
High7.3Sep 30
A trust-boundary flaw in CRI-O's sandbox state persistence
High7.8Sep 30
Red Hat libsoup.: buffer overflow
High8.6Sep 29
Red Hat libsoup.: buffer overflow
High8.6Sep 29
Red Hat libsoup.: buffer overflow
High8.6Sep 29

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.