7.8 HIGH
- CVSS version (CVSS): 3.1
- Attack Vector (AV): Local (L)
- Attack Complexity (AC): Low (L)
- Privileges Required (PR): None (N)
- User Interaction (UI): Required (R)
- Scope (S): Unchanged (U)
- Confidentiality (C): High (H)
- Integrity (I): High (H)
- Availability (A): High (H)
- Modified Attack Vector (MAV): Local (L)
- Modified Attack Complexity (MAC): Low (L)
- Modified Privileges Required (MPR): None (N)
- Modified User Interaction (MUI): Required (R)
- Modified Confidentiality (MC): High (H)
- Modified Scope (MS): Unchanged (U)
- Modified Integrity (MI): High (H)
- Modified Availability (MA): High (H)
by @LeSuisse Activity log
- Created suggestion
-
@LeSuisse
ignored
19 packages
- makerpm
- rpm2targz
- rpm-ostree
- rpmextract
- rpm-sequoia
- perlPackages.RPM2
- perl5Packages.RPM2
- python313Packages.rpm
- python314Packages.rpm
- haskellPackages.rpm-nvr
- haskellPackages.cabal-rpm
- python313Packages.rpmfile
- python314Packages.rpmfile
- python313Packages.rpmfluff
- python314Packages.rpmfluff
- haskellPackages.select-rpms
- tree-sitter-grammars.tree-sitter-rpmspec
- python313Packages.tree-sitter-grammars.tree-sitter-rpmspec
- python314Packages.tree-sitter-grammars.tree-sitter-rpmspec
- @LeSuisse accepted
- @LeSuisse published on GitHub
Rpm: command injection in `rpmbuild -t*` (`gettarspec`) via unescaped tarball path
A flaw was found in rpm. An attacker can exploit a command injection vulnerability by influencing the path or filename of a tarball processed by `rpmbuild -t*` to include shell metacharacters. This is particularly relevant in automated build or continuous integration (CI) workflows that ingest externally supplied artifact names. Successful exploitation allows for arbitrary command execution with the privileges of the build user, which could lead to information disclosure or disruption of the build environment.
References
Affected products
Matching in nixpkgs
Ignored packages (19)
pkgs.makerpm
Clean, simple RPM packager reimplemented completely from scratch
pkgs.rpm2targz
Convert a .rpm file to a .tar.gz archive
-
nixos-unstable 2021.03.16
- nixpkgs-unstable 2021.03.16
- nixos-unstable-small 2021.03.16
-
nixos-26.05 2021.03.16
- nixos-26.05-small 2021.03.16
- nixpkgs-26.05-darwin 2021.03.16
pkgs.rpm-ostree
Hybrid image/package system. It uses OSTree as an image format, and uses RPM as a component model
pkgs.rpmextract
Script to extract RPM archives
-
nixos-unstable -
- nixpkgs-unstable
- nixos-unstable-small 4.20.1
pkgs.rpm-sequoia
OpenPGP backend for rpm using Sequoia PGP
pkgs.perlPackages.RPM2
Perl bindings for the RPM Package Manager API
pkgs.perl5Packages.RPM2
Perl bindings for the RPM Package Manager API
pkgs.python313Packages.rpm
RPM package manager
pkgs.python314Packages.rpm
RPM package manager
pkgs.haskellPackages.rpm-nvr
RPM package name-version-release data types
pkgs.haskellPackages.cabal-rpm
RPM packaging tool for Haskell Cabal-based packages
pkgs.python313Packages.rpmfile
Read rpm archive files
pkgs.python314Packages.rpmfile
Read rpm archive files
pkgs.python313Packages.rpmfluff
Lightweight way of building RPMs, and sabotaging them
pkgs.python314Packages.rpmfluff
Lightweight way of building RPMs, and sabotaging them
pkgs.haskellPackages.select-rpms
Select a subset of RPM packages
pkgs.tree-sitter-grammars.tree-sitter-rpmspec
Tree-sitter grammar for rpmspec
-
nixos-unstable -
- nixos-unstable-small 0-unstable-2025-08-11
pkgs.python313Packages.tree-sitter-grammars.tree-sitter-rpmspec
Python bindings for tree-sitter-rpmspec
-
nixos-unstable -
- nixos-unstable-small 0+unstable20250811
pkgs.python314Packages.tree-sitter-grammars.tree-sitter-rpmspec
Python bindings for tree-sitter-rpmspec
-
nixos-unstable -
- nixos-unstable-small 0+unstable20250811