Race condition in RPM 4.11.1 and earlier allows remote attackers to execute arbitrary code via a crafted RPM file whose installation extracts the contents to temporary files before validating the signature, as demonstrated by installing a file in the /etc/cron.d directory.
CVSS Details
- CVSS 3.1 Base Score: 7.5
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Centos_linux | — | Upgrade rpm-buildUpgrade rpm-libsUpgrade rpm-cronUpgrade rpm-apidocsUpgrade rpm-develUpgrade poptUpgrade rpm-signUpgrade rpm-build-libsUpgrade rpm-pythonUpgrade rpm | Dec 1, 2016 | Dec 16, 2014 |
| Debian | — | Upgrade rpm | Jul 30, 2024 | Dec 16, 2014 |
| F5 Big Ip | — | Update F5 BIG-IP to the latest version | Jun 17, 2026 | Sep 11, 2015 |
| Gentoo Linux | — | Upgrade app-arch/rpm. | Nov 29, 2018 | Dec 16, 2014 |
| Oracle_linux | — | Upgrade rpm-libsUpgrade rpm-cronUpgrade rpm-build-libsUpgrade rpm-apidocsUpgrade rpm-pythonUpgrade rpm-develUpgrade rpm-signUpgrade poptUpgrade rpmUpgrade rpm-build | Oct 16, 2024 | Dec 16, 2014 |
| Suse | — | Upgrade rpm-pythonUpgrade popt-x86Upgrade rpm-32bitUpgrade rpm-develUpgrade popt-develUpgrade python3-rpmUpgrade popt-devel-32bitUpgrade rpm-x86Upgrade poptUpgrade rpm-devel-32bitUpgrade sle-sdk-releaseUpgrade rpm-buildUpgrade popt-32bitUpgrade rpm | Feb 17, 2015 | Dec 16, 2014 |
| Ubuntu | — | Upgrade rpm | Nov 8, 2024 | Dec 16, 2014 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub