VYPR

rpm

by Rpm Software Management

CVEs (2)

  • CVE-2026-78367HigAug 24, 2026
    risk 0.46cvss 7.0epss 0.00

    A vulnerability was found in RPM's rpmbuild tarball processing. When processing a crafted source archive, the getTarSpec() function in tools/rpmbuild.cc passes an attacker-controlled tar archive member name to rpmExpand() as part of a %{basename:...} macro expression. A…

  • CVE-2021-35938MedAug 25, 2022
    risk 0.44cvss 6.7epss 0.01

    A symbolic link issue was found in rpm. It occurs when rpm sets the desired permissions and credentials after installing a file. A local unprivileged user could use this flaw to exchange the original file with a symbolic link to a security-critical file and escalate their…