CVE-2026-103242: Rpm: heap-based buffer overflow write in hex2binv() via a mistyped rpmtag_filesignatures header tag

Published Sep 30, 2026
·
Updated

A heap-based buffer overflow flaw was found in rpm. RPMTAGFILESIGNATURES in a crafted, unsigned RPM package's main header is declared with the wrong header type, causing hex2binv() to allocate a one-byte buffer and then write the tag's attacker-controlled, hex-decoded content — of attacker-chosen length — past the end of that allocation. This is reachable via rpm2cpio, rpm2archive, and rpm -qlvp on an untrusted package.

Other sources

A heap-based buffer overflow write was found in RPM's hex2binv() function (lib/rpmfi.cc). In a crafted, unsigned RPM v4 package, the RPMTAGFILESIGNATURES tag in the main header is declared with type RPMI18NSTRINGTYPE (9) instead of its intended RPMSTRINGARRAYTYPE (8). This mismatch causes headerGet() to route the tag through copyI18NEntry(), which sets the tag's count and data but never sets its size field. hex2binv() sizes its output buffer from that (unset, and therefore zero) size, allocating only one byte, while its decode loop then writes half the length of the attacker-controlled hex string into that one-byte buffer -- an overflow of arbitrary, attacker-chosen length past the allocation.

The flaw is reachable by any command or library caller that populates rpmfi/rpmfiles data from an untrusted package's file signatures, such as rpm -qlvp, rpm2cpio, or rpm2archive. No package signature is required, since these tools do not validate package signatures by default. The issue was confirmed against the shipped rpm binary on Fedora Linux 44 (rpm-6.0.2): Valgrind reports an invalid one-byte write immediately past a one-byte heap allocation inside rpmfilesNew() (the inlined caller of hex2binv()), and a larger crafted payload reliably crashes the process with SIGSEGV.

— Red Hat

Affected Software

1 affected component
RPM RPM=6.0.2

Event History

Sep 30, 2026
Data Sourced
via Red Hat·10:27 AM
DescriptionSeverityAffected Software
CVE Published
via MITRE·11:50 AM
Data Sourced
via MITRE·11:50 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·12:17 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Which workflows can process a malicious package and trigger the overflow?

The issue is reachable when an untrusted RPM package is processed with rpm2cpio, rpm2archive, or rpm -qlvp. It can also affect library callers that populate file-signature information from the package header.

2

What does an attacker need to provide for exploitation?

An attacker needs to convince a user or local process to handle a crafted, unsigned RPM v4 package. The package's main header must contain RPMTAG_FILESIGNATURES declared as RPM_I18NSTRING_TYPE rather than RPM_STRING_ARRAY_TYPE, with attacker-controlled hexadecimal content.

3

Is installing the package required to be affected?

No. The vulnerable parsing path is reached by the listed package-inspection and extraction commands when they process the untrusted package; the description does not require installation.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203