
Found a vulnerability in RPM "rpmbuild" tarball processing: a crafted ".spec" member name can inject RPM macros, including Lua expressions, leading to arbitrary code execution. CVE-2026-78367 GitHub: https://github.com/rpm-software-management/rpm/issues/4314 CVE: https://www.cve.org/CVERecord?id=CVE-2026-78367 #CVE #RPM #Linux #RedHat
Post summary
The text announces the discovery of CVE‑2026‑78367, detailing how crafted spec files can inject macros for arbitrary code execution, but it provides no PoC, exploit code, or patch information.

