Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
4002 articles · 197512 vulns · 37/41 feeds (7d)
← Back to list
7.0
CVE-2026-78367EXPLOITED
red hat · red hat enterprise linux

Rpm: rpmbuild gettarspec() crafted tar member name → macro injection

Description

A vulnerability was found in RPM's rpmbuild tarball processing. When processing a crafted source archive, the getTarSpec() function in tools/rpmbuild.cc passes an attacker-controlled tar archive member name to rpmExpand() as part of a %{basename:...} macro expression. A specially crafted .spec member name can therefore inject RPM macros, including Lua expressions, resulting in arbitrary code execution with the privileges of the user running rpmbuild. This can be exploited when a victim or automated build system processes an attacker-controlled source tarball using rpmbuild tarball mode (such as -ts, -ta, or -tb).

Affected Products

VendorProductVersions
red hatred hat enterprise linux—

Also Affects

Downstream vendors/products affected by this vulnerability

VendorProductSourceConfidence
open sourceopen source rpmcert_advisory90%

References

  • https://access.redhat.com/security/cve/CVE-2026-78367(vdb-entry, x_refsource_REDHAT)
  • https://bugzilla.redhat.com/show_bug.cgi?id=2521857(issue-tracking, x_refsource_REDHAT)
  • https://github.com/rpm-software-management/rpm/issues/4314

Related News (2 articles)

Tier B
BSI Advisories18h ago
[NEU] [UNGEPATCHT] [mittel] RPM: Schwachstelle ermöglicht Ausführen von beliebigem Programmcode mit Benutzerrechten
→ No new info (linked only)
Tier C
VulDB1d ago
CVE-2026-78367 | Red Hat Enterprise Linux Tarball Mode injection
→ No new info (linked only)
CVSS 3.17.0 NONE
CISA KEV❌ No
Actively exploited✅ Yes
CWECWE-94
PublishedAug 24, 2026
Last enriched1d ago
Tags
remote code executionfile manipulationdenial of servicemultiple vulnerabilities
Trending Score58
Source articles2
Independent2
Info Completeness0/14
Missing: cve_id, title, description, vendor, product, versions, cvss, epss, cwe, kev, exploit, patch, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

NONECVE-2026-78465EXP
Gimp: integer overflow in pcx loader (planes=4) leads to heap overflow on 32-bit
Trending: 58
HIGHCVE-2026-79655EXP
Sos: sos: path traversal in sos clean tar extraction via unvalidated symlink/hardlink targets leads to arbitrary file write
Trending: 56
NONECVE-2026-18963
Keycloak-services: keycloak-services: unauthenticated account takeover via reset-credentials flow bypass
Trending: 54
CRITICALCVE-2026-19685EXP
Networkmanager: networkmanager: 802-1x ca-path and phase2-ca-path bypass private_user restriction, allowing wpa-enterprise server validation bypass (incomplete fix for cve-2025-9615)
Trending: 53
NONECVE-2026-14613EXP
Keycloak-services: keycloak-services: keycloak: fgap v2 role groups endpoint discloses hidden group metadata without group view permission
Trending: 50

Pin to Dashboard

Verification

State: unverified
Confidence: 0%

Vulnerability Timeline

CVE Published
Aug 24, 2026
Discovered by ZDM
Aug 24, 2026
Actively Exploited
Aug 24, 2026
Exploit Available
Aug 24, 2026