Race condition in RPM 4.11.1 and earlier allows remote attackers to execute arbitrary code via a crafted RPM file whose installation extracts the contents to temporary files before validating the signature, as demonstrated by installing a file in the /etc/cron.d directory.
CVSS Details
- CVSS 3.1 Base Score: 7.5
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Centos_linux | — | Upgrade rpm-build-libsUpgrade poptUpgrade rpmUpgrade rpm-develUpgrade rpm-pythonUpgrade rpm-signUpgrade rpm-buildUpgrade rpm-apidocsUpgrade rpm-cronUpgrade rpm-libs | Dec 1, 2016 | Dec 16, 2014 |
| Debian | — | Upgrade rpm | Jul 30, 2024 | Dec 16, 2014 |
| F5 Big Ip | — | Update F5 BIG-IP to the latest version | Jun 17, 2026 | Sep 11, 2015 |
| Gentoo Linux | — | Upgrade app-arch/rpm. | Nov 29, 2018 | Dec 16, 2014 |
| Oracle_linux | — | Upgrade poptUpgrade rpmUpgrade rpm-buildUpgrade rpm-develUpgrade rpm-pythonUpgrade rpm-signUpgrade rpm-libsUpgrade rpm-apidocsUpgrade rpm-cronUpgrade rpm-build-libs | Oct 16, 2024 | Dec 16, 2014 |
| Suse | — | Upgrade rpm-buildUpgrade rpmUpgrade rpm-devel-32bitUpgrade poptUpgrade popt-32bitUpgrade sle-sdk-releaseUpgrade rpm-32bitUpgrade popt-devel-32bitUpgrade popt-develUpgrade python3-rpmUpgrade rpm-develUpgrade rpm-pythonUpgrade rpm-x86Upgrade popt-x86 | Feb 17, 2015 | Dec 16, 2014 |
| Ubuntu | — | Upgrade rpm | Nov 8, 2024 | Dec 16, 2014 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub