CVE-2026-103242

LOWCVSS 7.1 · HIGH

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

A heap-based buffer overflow flaw was found in rpm. RPMTAG_FILESIGNATURES in a crafted, unsigned RPM package's main header is declared with the wrong header type, causing hex2binv() to allocate a one-byte buffer and then write the tag's attacker-controlled, hex-decoded content — of attacker-chosen length — past the end of that allocation. This is reachable via rpm2cpio, rpm2archive, and rpm -qlvp on an untrusted package.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-122

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 2 mentions across 1 observed day

What's happening

  • 2 total mentions across 1 day

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-09-30: 209-30
Full discourse2 posts
  • VulDB 🛡@vuldb

    A new vulnerability with increased severity was disclosed for Red Hat Enterprise Linux (CVE-2026-103242) vuldb.​com/vuln/411982

    00010134
    2.3K followersView on X
  • Upwind Security MDR@UpwindMDR

    🚨High - rpm Heap Overflow via RPMTAG_FILESIGNATURES Type Confusion (CVE-2026-103242) rpm mis-parses RPMTAG_FILESIGNATURES in a crafted unsigned RPM header when the tag is declared with the wrong type, causing hex2binv() to allocate a 1-byte heap buffer then overflow it while decoding attacker-controlled hex data. Triggered by parsing untrusted packages via rpm2cpio, rpm2archive, or rpm -qlvp, leading to integrity/availability impact. 👉Affected: rpm ( RHEL versions 8/9/10 )

    0000051
    309 followersView on X

Explore more