CVE-2026-78367: Rpm: rpmbuild gettarspec() crafted tar member name → macro injection
A flaw was found in rpmbuild. When rpmbuild processes a crafted tarball in tarball mode, a specially designed tar member name can lead to macro injection. This vulnerability allows a remote attacker to execute arbitrary code on the system by convincing a user to build a malicious tarball.
Other sources
When rpmbuild runs in tarball mode (-ta / -tb / -ts, etc.), getTarSpec() extracts a .spec from the archive and renames it using the member name from tar’s verbose listing. That member name is concatenated into:
specFinal = rpmExpand("%{specdir}/%{basename:", tarbuf, "}", NULL);
A crafted .spec member name containing } closes %{basename:...} early. Text after the } is expanded as further RPM macros, including %{lua:} (full Lua stdlib, rpm.execute / rpm.spawn). The expanded string is used as the destination of rename() and as the spec path for the rest of the build.
This happens while locating the spec — before %prep. It is not “spec scripts run shell by design.” The victim only needs to run rpmbuild -ts (or -ta / -tb) on a crafted tarball.
This is a sibling / variant of CVE-2026-44604: untrusted archive metadata (here: tar member name; there: ZIP/7z/GEM top-level directory) is interpolated into a privileged expand/popen path. Different call site (getTarSpec vs rpmuncompress), same trust-boundary class. CVE-2026-44604 did not fix this path.
— Red Hat
Affected Software
Event History
Frequently Asked Questions
Who is exposed to this issue?
Users or build systems that run rpmbuild in tarball mode on untrusted tarballs are exposed. Exploitation requires the victim to invoke rpmbuild with options such as -ts, -ta, or -tb on an attacker-crafted archive.
Does the malicious archive need to contain build scripts that are executed?
No. The injection occurs while rpmbuild is locating and renaming the extracted spec file, before the %prep stage. A crafted tar member name can cause additional RPM macros to expand, including Lua macros capable of executing code.
What archive content is used for the injection?
The relevant input is the tar member name of the .spec file, as obtained from tar’s verbose listing. A } in that member name can terminate the intended %{basename:...} expansion and cause following text to be interpreted as RPM macros.