CyberRota Analysis
AI-GeneratedA heap-based buffer overflow vulnerability exists in the rpm utility when processing untrusted RPM packages with a specific symlink entry. This flaw allows attackers to exploit the integer overflow in iterReadArchiveNext(), leading to the potential execution of arbitrary code by writing beyond allocated memory. Organizations using rpm for package management should prioritize patching to mitigate the risk of exploitation.
Original NVD Description
A heap-based buffer overflow flaw was found in rpm. Parsing a symlink entry in an untrusted RPM package whose declared RPMTAG_LONGFILESIZES value is 0xFFFFFFFFFFFFFFFF causes an integer overflow in iterReadArchiveNext() that shrinks a buffer allocation to one byte, after which the payload's independently-controlled cpio filesize field is used to write attacker-controlled data past the end of that allocation. This is reachable via rpm2cpio, rpm2archive, and rpm -qlvp on an untrusted package.