A command injection vulnerability was discovered in the `rpmuncompress` utility of RPM. When extracting certain archive formats (ZIP, 7z, GEM) to a specified destination directory, the tool inserts the archive's top-level folder name into a shell command without properly sanitizing it. A specially crafted archive containing shell metacharacters in its folder name can execute arbitrary commands as the user running the extraction.
Project Subscriptions
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Thu, 28 May 2026 07:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A command injection vulnerability was discovered in the `rpmuncompress` utility of RPM. When extracting certain archive formats (ZIP, 7z, GEM) to a specified destination directory, the tool inserts the archive's top-level folder name into a shell command without properly sanitizing it. A specially crafted archive containing shell metacharacters in its folder name can execute arbitrary commands as the user running the extraction. | |
| Title | Rpm: command injection in rpmuncompress dountar() via unescaped archive top-level directory name in popen() shell command | |
| First Time appeared |
Redhat
Redhat enterprise Linux Redhat hummingbird Redhat openshift Redhat pdrive Lightspeed Redhat quarkus Redhat satellite |
|
| Weaknesses | CWE-78 | |
| CPEs | cpe:/a:redhat:hummingbird:1 cpe:/a:redhat:openshift:4 cpe:/a:redhat:pdrive_lightspeed:0 cpe:/a:redhat:quarkus:3 cpe:/a:redhat:satellite:6 cpe:/o:redhat:enterprise_linux:10 cpe:/o:redhat:enterprise_linux:6 cpe:/o:redhat:enterprise_linux:7 cpe:/o:redhat:enterprise_linux:8 cpe:/o:redhat:enterprise_linux:9 |
|
| Vendors & Products |
Redhat
Redhat enterprise Linux Redhat hummingbird Redhat openshift Redhat pdrive Lightspeed Redhat quarkus Redhat satellite |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2026-05-28T05:59:20.978Z
Reserved: 2026-05-07T03:57:03.811Z
Link: CVE-2026-44604
No data.
Status : Received
Published: 2026-05-28T08:16:35.280
Modified: 2026-05-28T08:16:35.280
Link: CVE-2026-44604
No data.
OpenCVE Enrichment
Updated: 2026-05-28T08:30:12Z
Weaknesses