OCTOBER 8, 2026
Live Feed
Back to database
Case File

CVE-2026-95520

HIGH · CVSS 7.1 EPSS 0.12%

Source: NVD + CISA KEV + EPSS · Published 2026-09-29 · Last synced 2026-10-08

CyberRota Analysis

AI-Generated

A heap-based buffer overflow vulnerability exists in the rpm utility when processing untrusted RPM packages with a specific symlink entry. This flaw allows attackers to exploit the integer overflow in iterReadArchiveNext(), leading to the potential execution of arbitrary code by writing beyond allocated memory. Organizations using rpm for package management should prioritize patching to mitigate the risk of exploitation.

CVE
CVE-2026-95520
Severity
HIGH
CVSS
7.1
EPSS
0.12%

Original NVD Description

A heap-based buffer overflow flaw was found in rpm. Parsing a symlink entry in an untrusted RPM package whose declared RPMTAG_LONGFILESIZES value is 0xFFFFFFFFFFFFFFFF causes an integer overflow in iterReadArchiveNext() that shrinks a buffer allocation to one byte, after which the payload's independently-controlled cpio filesize field is used to write attacker-controlled data past the end of that allocation. This is reachable via rpm2cpio, rpm2archive, and rpm -qlvp on an untrusted package.