CVE-2026-78367Disclosure

LOWCVSS 7.0 · HIGH

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

A vulnerability was found in RPM's rpmbuild tarball processing. When processing a crafted source archive, the getTarSpec() function in tools/rpmbuild.cc passes an attacker-controlled tar archive member name to rpmExpand() as part of a %{basename:...} macro expression. A specially crafted .spec member name can therefore inject RPM macros, including Lua expressions, resulting in arbitrary code execution with the privileges of the user running rpmbuild. This can be exploited when a victim or automated build system processes an attacker-controlled source tarball using rpmbuild tarball mode (such as -ts, -ta, or -tb).

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-94

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 2 mentions across 1 observed day

What's happening

  • Technical details provided in 1 signal
  • Disclosure: 2 classified signals
  • 2 total mentions across 1 day

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-08-24: 2Technical Details · 2026-08-24: 108-24
Signal classification1 categories
Disclosure
2100.0%
Referenced assets3 URLs
Full discourse2 posts
  • Sandipan Roy@ByteHackr
    Disclosure

    Found a vulnerability in RPM "rpmbuild" tarball processing: a crafted ".spec" member name can inject RPM macros, including Lua expressions, leading to arbitrary code execution. CVE-2026-78367 GitHub: https://github.com/rpm-software-management/rpm/issues/4314 CVE: https://www.cve.org/CVERecord?id=CVE-2026-78367 #CVE #RPM #Linux #RedHat

    Post summary

    The text announces the discovery of CVE‑2026‑78367, detailing how crafted spec files can inject macros for arbitrary code execution, but it provides no PoC, exploit code, or patch information.

    0000099
    196 followersView on X
  • VulDB 🛡@vuldb
    Disclosure

    A severe vulnerability was disclosed for Red Hat Enterprise Linux and other products (CVE-2026-78367) https://vuldb.com/vuln/394683

    Post summary

    A severe vulnerability (CVE-2026-78367) affecting Red Hat Enterprise Linux and other products was disclosed, with more information linked but no evidence of exploitation or mitigation.

    00000131
    2.3K followersView on X

Explore more