7.8 HIGH
- CVSS version (CVSS): 3.1
- Attack Vector (AV): Local (L)
- Attack Complexity (AC): Low (L)
- Privileges Required (PR): None (N)
- User Interaction (UI): Required (R)
- Scope (S): Unchanged (U)
- Confidentiality (C): High (H)
- Integrity (I): High (H)
- Availability (A): High (H)
- Modified Attack Vector (MAV): Local (L)
- Modified Attack Complexity (MAC): Low (L)
- Modified Privileges Required (MPR): None (N)
- Modified User Interaction (MUI): Required (R)
- Modified Confidentiality (MC): High (H)
- Modified Scope (MS): Unchanged (U)
- Modified Integrity (MI): High (H)
- Modified Availability (MA): High (H)
by @LeSuisse Activity log
- Created suggestion
-
@LeSuisse
ignored
19 packages
- makerpm
- rpm2targz
- rpm-ostree
- rpmextract
- rpm-sequoia
- perlPackages.RPM2
- perl5Packages.RPM2
- python313Packages.rpm
- python314Packages.rpm
- haskellPackages.rpm-nvr
- haskellPackages.cabal-rpm
- python313Packages.rpmfile
- python314Packages.rpmfile
- python313Packages.rpmfluff
- python314Packages.rpmfluff
- haskellPackages.select-rpms
- tree-sitter-grammars.tree-sitter-rpmspec
- python313Packages.tree-sitter-grammars.tree-sitter-rpmspec
- python314Packages.tree-sitter-grammars.tree-sitter-rpmspec
- @LeSuisse accepted
- @LeSuisse published on GitHub
Rpm: code execution via macro expansion of manifest entries in `rpmgi` (`-q -p` / verify manifest flows)
A flaw was found in rpm. An attacker can supply a crafted manifest file that, when processed by a user or automation using `rpm -q -p` or similar manifest-processing flows, leads to arbitrary code execution. This occurs because manifest entries are unexpectedly macro-expanded before being opened, allowing embedded shell commands to run with the privileges of the `rpm` process. Successful exploitation can lead to a full compromise of confidentiality, integrity, and availability for the affected account.
References
Affected products
Matching in nixpkgs
Ignored packages (19)
pkgs.makerpm
Clean, simple RPM packager reimplemented completely from scratch
pkgs.rpm2targz
Convert a .rpm file to a .tar.gz archive
-
nixos-unstable -
- nixos-unstable-small 2021.03.16
-
nixos-26.05 -
- nixos-26.05-small 2021.03.16
pkgs.rpm-ostree
Hybrid image/package system. It uses OSTree as an image format, and uses RPM as a component model
pkgs.rpmextract
Script to extract RPM archives
-
nixos-unstable -
- nixos-unstable-small 4.20.1
pkgs.rpm-sequoia
OpenPGP backend for rpm using Sequoia PGP
pkgs.perlPackages.RPM2
Perl bindings for the RPM Package Manager API
pkgs.perl5Packages.RPM2
Perl bindings for the RPM Package Manager API
pkgs.python313Packages.rpm
RPM package manager
pkgs.python314Packages.rpm
RPM package manager
pkgs.haskellPackages.rpm-nvr
RPM package name-version-release data types
pkgs.haskellPackages.cabal-rpm
RPM packaging tool for Haskell Cabal-based packages
pkgs.python313Packages.rpmfile
Read rpm archive files
pkgs.python314Packages.rpmfile
Read rpm archive files
pkgs.python313Packages.rpmfluff
Lightweight way of building RPMs, and sabotaging them
pkgs.python314Packages.rpmfluff
Lightweight way of building RPMs, and sabotaging them
pkgs.haskellPackages.select-rpms
Select a subset of RPM packages
pkgs.tree-sitter-grammars.tree-sitter-rpmspec
Tree-sitter grammar for rpmspec
-
nixos-unstable -
- nixos-unstable-small 0-unstable-2025-08-11
pkgs.python313Packages.tree-sitter-grammars.tree-sitter-rpmspec
Python bindings for tree-sitter-rpmspec
-
nixos-unstable -
- nixos-unstable-small 0+unstable20250811
pkgs.python314Packages.tree-sitter-grammars.tree-sitter-rpmspec
Python bindings for tree-sitter-rpmspec
-
nixos-unstable -
- nixos-unstable-small 0+unstable20250811