Red HatCVE-2026-84837
Red Hat rpm: command injection
High7.8CVE-2026-84837 · Published Sep 2, 2026 · updated Sep 3, 2026
A flaw was found in rpm. An attacker can exploit a command injection vulnerability by influencing the path or filename of a tarball processed by `rpmbuild -t*` to include shell metacharacters. This is particularly relevant in automated build or continuous integration (CI) workflows that ingest externally supplied artifact names. Successful exploitation allows for arbitrary command execution with the privileges of the build user, which could lead to information disclosure or disruption of the build environment.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| Red Hat Enterprise Linux 10 Product | all versions | No fix yet |
| Red Hat Enterprise Linux 6 Product | all versions | No fix yet |
| Red Hat Enterprise Linux 7 Product | all versions | No fix yet |
| Red Hat Enterprise Linux 8 Product | all versions | No fix yet |
| Red Hat Enterprise Linux 9 Product | all versions | No fix yet |
| Red Hat Hardened Images Product | all versions | No fix yet |
Details and references
- CVSS 3.1
- CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
- Severity from
- the vendor (its own CVE record or advisory)
- Weakness
- CWE-78
More Red Hat advisories
All Red Hat| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Sep 2 | Red Hat Advanced Cluster Management for Kubernetes 2: remote code execution | Critical9.1 | No fix yet |
| Sep 2 | Red Hat Enterprise Linux 10: command injection | High7.8 | No fix yet |
| Sep 2 | The nsenter --join-cgroup option opens the target cgroup.procs file as root and... | High7.9 | No fix yet |
| Sep 2 | Red Hat Enterprise Linux 10: link following | High7.0 | No fix yet |
| Sep 2 | Red Hat util-linux: race condition | High7.8 | No fix yet |
| Sep 2 | Red Hat Enterprise Linux: open redirect | Medium4.3 | No fix yet |