CVE-2026-95520: Rpm: rpm: integer overflow in iterreadarchivenext() leads to heap-based buffer overflow when parsing untrusted rpm packages
A heap-based buffer overflow flaw was found in rpm. Parsing a symlink entry in an untrusted RPM package whose declared RPMTAGLONGFILESIZES value is 0xFFFFFFFFFFFFFFFF causes an integer overflow in iterReadArchiveNext() that shrinks a buffer allocation to one byte, after which the payload's independently-controlled cpio filesize field is used to write attacker-controlled data past the end of that allocation. This is reachable via rpm2cpio, rpm2archive, and rpm -qlvp on an untrusted package.
Other sources
A heap-based buffer overflow flaw was found in rpm. When iterReadArchiveNext() processes a symlink entry in an RPM package payload, it reads the target size from the package header as a 64-bit value and allocates a buffer with xmalloc(lsize + 1) at lib/rpmfi.cc:2229. Because there is no upper bound on the header-declared size, a package that sets RPMTAGLONGFILESIZES to 0xFFFFFFFFFFFFFFFF causes the addition to wrap to zero, so only a 1-byte buffer is allocated. The subsequent rpmcpioRead() call at lib/rpmfi.cc:2230 then copies into that buffer using the payload's independent cpio-header filesize field, which is entirely attacker-controlled and unrelated to the wrapped size, resulting in a heap write of attacker-chosen length and content past the end of the allocation. The archive iterator that reaches this code is entered by the shipped front ends rpm2cpio and rpm2archive (which disable header/signature checks by default) and by rpm -qlvp, so simply parsing or extracting an untrusted .rpm file, without needing a valid signature, triggers the overflow; the same iterator is also entered on the install path. This was confirmed by reproducing the reporter's proof of concept with an AddressSanitizer-instrumented build of rpm at both rpm-6.1.0-release and master, which showed reliable heap-buffer-overflow WRITEs of package-chosen lengths (demonstrated at 256, 4096, and 16248 bytes), each into a 1-byte region allocated at rpmfi.cc:2229, with a negative control (a byte-identical package carrying a truthful LONGFILESIZES value) producing no overflow.
— Red Hat
Affected Software
Event History
Frequently Asked Questions
What must an attacker provide to trigger the flaw?
The attacker must supply a crafted RPM package containing a symlink entry with RPMTAG_LONGFILESIZES set to 0xFFFFFFFFFFFFFFFF and an independently controlled cpio payload filesize. No prior privileges are required, but a user must parse the untrusted package.
Which RPM operations are known to reach the vulnerable code?
The issue is reachable through rpm2cpio, rpm2archive, and rpm -qlvp when they process an untrusted RPM package.
What is the practical effect of the malformed package?
The declared size can overflow during allocation and leave a one-byte heap buffer. The package payload can then cause attacker-controlled data to be written past that buffer.
What can be done while a fix is unavailable?
Do not use rpm2cpio, rpm2archive, or rpm -qlvp on RPM packages from untrusted sources. Restrict package inspection and extraction to packages obtained through trusted channels.