CVE-2026-95520: Rpm: rpm: integer overflow in iterreadarchivenext() leads to heap-based buffer overflow when parsing untrusted rpm packages

Published Sep 22, 2026
·
Updated

A heap-based buffer overflow flaw was found in rpm. Parsing a symlink entry in an untrusted RPM package whose declared RPMTAGLONGFILESIZES value is 0xFFFFFFFFFFFFFFFF causes an integer overflow in iterReadArchiveNext() that shrinks a buffer allocation to one byte, after which the payload's independently-controlled cpio filesize field is used to write attacker-controlled data past the end of that allocation. This is reachable via rpm2cpio, rpm2archive, and rpm -qlvp on an untrusted package.

Other sources

A heap-based buffer overflow flaw was found in rpm. When iterReadArchiveNext() processes a symlink entry in an RPM package payload, it reads the target size from the package header as a 64-bit value and allocates a buffer with xmalloc(lsize + 1) at lib/rpmfi.cc:2229. Because there is no upper bound on the header-declared size, a package that sets RPMTAGLONGFILESIZES to 0xFFFFFFFFFFFFFFFF causes the addition to wrap to zero, so only a 1-byte buffer is allocated. The subsequent rpmcpioRead() call at lib/rpmfi.cc:2230 then copies into that buffer using the payload's independent cpio-header filesize field, which is entirely attacker-controlled and unrelated to the wrapped size, resulting in a heap write of attacker-chosen length and content past the end of the allocation. The archive iterator that reaches this code is entered by the shipped front ends rpm2cpio and rpm2archive (which disable header/signature checks by default) and by rpm -qlvp, so simply parsing or extracting an untrusted .rpm file, without needing a valid signature, triggers the overflow; the same iterator is also entered on the install path. This was confirmed by reproducing the reporter's proof of concept with an AddressSanitizer-instrumented build of rpm at both rpm-6.1.0-release and master, which showed reliable heap-buffer-overflow WRITEs of package-chosen lengths (demonstrated at 256, 4096, and 16248 bytes), each into a 1-byte region allocated at rpmfi.cc:2229, with a negative control (a byte-identical package carrying a truthful LONGFILESIZES value) producing no overflow.

— Red Hat

Affected Software

1 affected component
RPM RPM=6.1.0

Event History

Sep 22, 2026
Data Sourced
via Red Hat·10:33 AM
DescriptionSeverityAffected Software
Sep 29, 2026
CVE Published
via MITRE·11:02 AM
Data Sourced
via MITRE·11:02 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·12:17 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

What must an attacker provide to trigger the flaw?

The attacker must supply a crafted RPM package containing a symlink entry with RPMTAG_LONGFILESIZES set to 0xFFFFFFFFFFFFFFFF and an independently controlled cpio payload filesize. No prior privileges are required, but a user must parse the untrusted package.

2

Which RPM operations are known to reach the vulnerable code?

The issue is reachable through rpm2cpio, rpm2archive, and rpm -qlvp when they process an untrusted RPM package.

3

What is the practical effect of the malformed package?

The declared size can overflow during allocation and leave a one-byte heap buffer. The package payload can then cause attacker-controlled data to be written past that buffer.

4

What can be done while a fix is unavailable?

Do not use rpm2cpio, rpm2archive, or rpm -qlvp on RPM packages from untrusted sources. Restrict package inspection and extraction to packages obtained through trusted channels.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203