A flaw was found in the RPM Package Manager (RPM). A local user could be affected by a heap buffer overflow vulnerability when processing a specially crafted NDB database file. This issue arises from an error in how RPM handles certain calculations during file parsing, leading to an incorrect memory allocation. An attacker could leverage this to cause a denial of service, making the system unavailable.
CVSS Details
- CVSS 3.1 Base Score: 5.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Amazon_linux_2023 | — | Upgrade rpm-signUpgrade rpm-develUpgrade rpm-plugin-fapolicydUpgrade rpm-plugin-selinux-debuginfoUpgrade rpm-sign-libs-debuginfoUpgrade rpm-plugin-prioreset-debuginfoUpgrade python3-rpmUpgrade rpm-plugin-auditUpgrade rpm-sign-debuginfoUpgrade rpm-debugsourceUpgrade rpm-plugin-systemd-inhibitUpgrade rpm-cronUpgrade rpm-libsUpgrade rpm-sign-libsUpgrade rpm-plugin-selinuxUpgrade rpm-build-libs-debuginfoUpgrade rpm-apidocsUpgrade rpm-plugin-syslog-debuginfoUpgrade rpmUpgrade rpm-libs-debuginfoUpgrade rpm-buildUpgrade rpm-plugin-ima-debuginfoUpgrade rpm-plugin-syslogUpgrade rpm-devel-debuginfoUpgrade python3-rpm-debuginfoUpgrade rpm-debuginfoUpgrade rpm-plugin-audit-debuginfoUpgrade rpm-build-libsUpgrade rpm-build-debuginfoUpgrade rpm-plugin-imaUpgrade rpm-plugin-systemd-inhibit-debuginfoUpgrade rpm-plugin-prioresetUpgrade rpm-plugin-fapolicyd-debuginfo | Aug 10, 2026 | Aug 5, 2026 |
| Redhat_linux | — | No solution exists | Sep 2, 2026 | May 28, 2026 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub