CVE-2026-44604

Discovered by AISLEPUBLISHEDCWE-78

Description

A command injection vulnerability was discovered in the `rpmuncompress` utility of RPM. When extracting certain archive formats (ZIP, 7z, GEM) to a specified destination directory, the tool inserts the archive's top-level folder name into a shell command without properly sanitizing it. A specially crafted archive containing shell metacharacters in its folder name can execute arbitrary commands as the user running the extraction.

CVSS Base Scores

CVSS v3.1(Primary)
7.0

CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H

Affected Products

VendorProductVersionStatus
Red HatRed Hat Hardened Images6.0.1-6.1.hum1unaffected
Red HatRed Hat Enterprise Linux 10——
Red HatRed Hat Enterprise Linux 6——
Red HatRed Hat Enterprise Linux 7——
Red HatRed Hat Enterprise Linux 8——
Red HatRed Hat Enterprise Linux 9——

Credits

  • This issue was discovered by Found by AISLE in partnership with Red Hat.

References