Red Hat RPM: code execution
High7.0CVE-2026-78367 · Published Aug 24, 2026 · updated Sep 4, 2026
A vulnerability was found in RPM's rpmbuild tarball processing. When processing a crafted source archive, the getTarSpec() function in tools/rpmbuild.cc passes an attacker-controlled tar archive member name to rpmExpand() as part of a %{basename:...} macro expression. A specially crafted .spec member name can therefore inject RPM macros, including Lua expressions, resulting in arbitrary code execution with the privileges of the user running rpmbuild. This can be exploited when a victim or automated build system processes an attacker-controlled source tarball using rpmbuild tarball mode (such as -ts, -ta, or -tb).
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| Red Hat Enterprise Linux 10 Product | all versions | No fix yet |
| Red Hat Enterprise Linux 6 Product | all versions | No fix yet |
| Red Hat Enterprise Linux 7 Product | all versions | No fix yet |
| Red Hat Enterprise Linux 8 Product | all versions | No fix yet |
| Red Hat Enterprise Linux 9 Product | all versions | No fix yet |
| Red Hat Hardened Images Product | all versions | No fix yet |
Details and references
- CVSS 3.1
- CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
- Severity from
- the vendor (its own CVE record or advisory)
- Weakness
- CWE-94
More Red Hat advisories
All Red Hat| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Aug 24 | A flaw was found in CRI-O's container-creation environment-variable handling | Medium6.0 | Red Hat+5 more |
| Aug 24 | Red Hat GIMP: denial of service | Medium6.1 | No fix yet |
| Aug 24 | Red Hat file-pcx plugin: integer overflow | High7.0 | No fix yet |
| Aug 24 | Red Hat Enterprise Linux 10: improper authorization | High7.1 | No fix yet |
| Aug 24 | Red Hat AWX: path traversal | High7.2 | No fix yet |
| Aug 24 | Red Hat multiple AWX: server-side request forgery | High7.7 | No fix yet |