CVE-2026-95520: 
Linux Red Hat vulnerability analysis and mitigation

Overview

CVE-2026-95520 is a heap-based buffer overflow vulnerability in the rpm package manager caused by an integer overflow in the iterReadArchiveNext() function. When parsing a symlink entry in an untrusted RPM package with a RPMTAG_LONGFILESIZES value of 0xFFFFFFFFFFFFFFFF, the addition wraps to zero, resulting in a 1-byte buffer allocation; the payload's independently-controlled cpio filesize field then writes attacker-controlled data past the end of that allocation. The vulnerability is reachable via rpm2cpio, rpm2archive, and rpm -qlvp when processing untrusted packages. It was disclosed on September 29, 2026, and carries a CVSS v3.1 base score of 7.1 (High) (Red Hat CVE, Github Advisory).

Technical details

The root cause is an integer overflow (CWE-787: Out-of-bounds Write) in iterReadArchiveNext() at lib/rpmfi.cc:2229. When a symlink entry's RPMTAG_LONGFILESIZES header field is set to 0xFFFFFFFFFFFFFFFF, the expression xmalloc(lsize + 1) wraps to zero, allocating only a 1-byte buffer. The subsequent rpmcpioRead() call at lib/rpmfi.cc:2230 then uses the payload's independent cpio-header filesize field — entirely attacker-controlled — to copy data into that 1-byte region, enabling a heap write of attacker-chosen length and content. Exploitation requires no valid RPM signature, as rpm2cpio and rpm2archive disable header/signature checks by default; a proof of concept confirmed reliable heap-buffer-overflow WRITEs of 256, 4096, and 16,248 bytes into the 1-byte allocation using an AddressSanitizer-instrumented build (Red Hat Bugzilla, Red Hat CVE).

Impact

Successful exploitation can result in high integrity and high availability impact, including memory corruption, potential arbitrary code execution, and application crashes. An attacker who can convince a user or automated workflow to process a crafted RPM package can corrupt heap memory, potentially leading to unauthorized code execution in the context of the invoking user. There is no confidentiality impact assessed, but the ability to modify memory and crash the process represents a significant risk in environments that automatically process RPM packages from untrusted sources (Red Hat CVE, Github Advisory).

Exploitability

A proof of concept was confirmed by Red Hat's security team using an AddressSanitizer-instrumented build, demonstrating reliable heap-buffer-overflow writes at multiple sizes (Red Hat Bugzilla). Exploitation requires local access and user interaction — a user or automated workflow must process the malicious RPM — but no privileges or valid package signature are required. As of the disclosure date, there is no evidence of in-the-wild exploitation, no known threat actor attribution, and the EPSS score is 0.0 (Github Advisory). The vulnerability is not listed in the CISA KEV catalog.

Exploitation steps

  1. Craft a malicious RPM package: Create an RPM package containing a symlink entry with RPMTAG_LONGFILESIZES set to 0xFFFFFFFFFFFFFFFF in the package header, and set the cpio payload's filesize field to a large attacker-controlled value (e.g., 256, 4096, or 16,248 bytes) with attacker-controlled content.
  2. Deliver the package: Distribute the crafted .rpm file to the target system via any channel (e.g., a malicious repository, email attachment, or social engineering), without requiring a valid RPM signature.
  3. Trigger processing: Induce the victim user or an automated workflow to process the package using one of the vulnerable front-end commands: rpm2cpio malicious.rpm, rpm2archive malicious.rpm, or rpm -qlvp malicious.rpm.
  4. Trigger integer overflow: When iterReadArchiveNext() processes the symlink entry, the xmalloc(0xFFFFFFFFFFFFFFFF + 1) call wraps to zero, allocating a 1-byte heap buffer.
  5. Achieve heap overflow: The subsequent rpmcpioRead() call uses the cpio filesize field to write attacker-controlled data of attacker-chosen length past the end of the 1-byte allocation, corrupting heap memory.
  6. Achieve objective: Depending on heap layout and target environment, the overflow may enable arbitrary code execution in the context of the invoking user, or cause a denial of service via crash (Red Hat Bugzilla, Red Hat CVE).

Indicators of compromise

  • Process: Unexpected crashes or segmentation faults in rpm, rpm2cpio, or rpm2archive processes when processing RPM files from untrusted or external sources.
  • Logs: System logs (e.g., /var/log/messages, journal) showing abnormal termination of rpm-related processes with signals such as SIGSEGV or SIGABRT.
  • File System: Presence of unusual or unsigned .rpm files in temporary directories or download locations, particularly those with symlink entries and anomalous file size metadata.
  • Process: AddressSanitizer or other memory-safety tool reports of heap-buffer-overflow WRITEs originating from rpmfi.cc:2229 or rpmfi.cc:2230 in instrumented builds.

Mitigation and workarounds

Red Hat has rated this issue as Moderate and a patch is in progress (tracked in Bugzilla bug 2537809). Until a fixed RPM package version is available, the primary mitigation is to avoid processing RPM packages from untrusted or unverified sources using rpm2cpio, rpm2archive, or rpm -qlvp. Organizations should enforce policies requiring RPM packages to be sourced only from trusted, signed repositories and verify package integrity before processing (Red Hat CVE, Red Hat Bugzilla).

Community reactions

Red Hat acknowledged the vulnerability and credited researcher tao pan for the report. Red Hat's product security team rated the issue as Moderate, noting that while the heap write is attacker-controlled, exploitation requires local user interaction and is not exposed as a network service (Red Hat CVE). No significant broader community or social media reactions have been observed as of the disclosure date.

Additional resources

Linux Distribution fix status

Fix availability across major Linux distributions and their releases.

Debian

Affected

bookworm

rpm

Affected

sid

rpm

Affected

trixie

rpm

Affected

RHEL / CentOS

Affected

RHEL 8

rpm.src

Affected

RHEL 9

rpm.src

Affected

RHEL 10

rpm.src

Affected

Source: This report was generated using AI

Related Linux Red Hat vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-95520HIGH7.1
  • Linux Red Hat logoLinux Red Hat
  • rpm-cron
NoNoSep 29, 2026
CVE-2026-96423MEDIUM5.5
  • Wireshark logoWireshark
  • wireshark.src
NoNoSep 29, 2026
CVE-2026-96422MEDIUM5.5
  • Wireshark logoWireshark
  • wireshark
NoNoSep 29, 2026
CVE-2026-96421MEDIUM5.5
  • Wireshark logoWireshark
  • wireshark-cli
NoNoSep 29, 2026
CVE-2026-96420MEDIUM4.7
  • Wireshark logoWireshark
  • wireshark.src
NoNoSep 29, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management