Nixpkgs security tracker

Try the new UI
Login with GitHub

Suggestion detail

Untriaged
Permalink CVE-2026-84838
7.8 HIGH
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Local (L)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): None (N)
  • User Interaction (UI): Required (R)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): High (H)
  • Integrity (I): High (H)
  • Availability (A): High (H)
  • Modified Attack Vector (MAV): Local (L)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): None (N)
  • Modified User Interaction (MUI): Required (R)
  • Modified Confidentiality (MC): High (H)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): High (H)
  • Modified Availability (MA): High (H)
updated 3 weeks, 2 days ago by @mweinelt Activity log
  • Created suggestion
  • @mweinelt ignored
    19 packages
    • makerpm
    • rpm2targz
    • rpm-ostree
    • rpmextract
    • rpm-sequoia
    • perlPackages.RPM2
    • perl5Packages.RPM2
    • python313Packages.rpm
    • python314Packages.rpm
    • haskellPackages.rpm-nvr
    • haskellPackages.cabal-rpm
    • python313Packages.rpmfile
    • python314Packages.rpmfile
    • python313Packages.rpmfluff
    • python314Packages.rpmfluff
    • haskellPackages.select-rpms
    • tree-sitter-grammars.tree-sitter-rpmspec
    • python313Packages.tree-sitter-grammars.tree-sitter-rpmspec
    • python314Packages.tree-sitter-grammars.tree-sitter-rpmspec
Rpm: command injection in rpmuncompress via unescaped filenames passed to popen()

A flaw was found in rpmuncompress. This command injection vulnerability allows a local attacker to execute arbitrary commands. This occurs when rpmuncompress processes a specially crafted archive filename containing shell metacharacters, which are not properly escaped before being passed to shell command strings. Successful exploitation requires user interaction, where a user or automated workflow invokes rpmuncompress on the malicious file, leading to high impact on the confidentiality, integrity, and availability of data accessible to the invoking user.

References

Affected products

rpm

Matching in nixpkgs

pkgs.rpm

RPM package manager

  • nixos-unstable -
  • nixos-26.05 -
Ignored packages (19)

pkgs.makerpm

Clean, simple RPM packager reimplemented completely from scratch

  • nixos-unstable -
    • nixos-unstable-small 1.0
  • nixos-26.05 -
    • nixos-26.05-small 1.0

pkgs.rpm2targz

Convert a .rpm file to a .tar.gz archive

pkgs.rpm-ostree

Hybrid image/package system. It uses OSTree as an image format, and uses RPM as a component model

  • nixos-unstable -
  • nixos-26.05 -

pkgs.rpmextract

Script to extract RPM archives

  • nixos-unstable -
  • nixos-26.05 -
    • nixos-26.05-small

pkgs.rpm-sequoia

OpenPGP backend for rpm using Sequoia PGP

  • nixos-unstable -
  • nixos-26.05 -

pkgs.perlPackages.RPM2

Perl bindings for the RPM Package Manager API

  • nixos-unstable -
    • nixos-unstable-small 1.4
  • nixos-26.05 -
    • nixos-26.05-small 1.4

pkgs.perl5Packages.RPM2

Perl bindings for the RPM Package Manager API

  • nixos-unstable -
    • nixos-unstable-small 1.4
  • nixos-26.05 -
    • nixos-26.05-small 1.4