rpm: Command injection in rpmuncompress via unescaped filenames passed to popen()

cve CVE-2026-84838 1 source, 1 claim · Watch

Red Hat writes:
rpm: Command injection in rpmuncompress via unescaped filenames passed to popen() the claim

What each source says

PropertySourceSaidMeans here
Cvss
cvss
Red Hat7.8
receipt
Source
Red Hat
Its words
7.8
Read by
field:cvss3_score
Said since
2026-09-29 09:44 UTC
Last answered
2026-10-02 18:04 UTC
Original
open at the source
What the source handed over
{
  "CVE": "CVE-2026-84838",
  "CWE": "CWE-78",
  "advisories": [],
  "affected_packages": [],
  "bugzilla": "2462222",
  "bugzilla_description": "rpm: Command injection in rpmuncompress via unescaped filenames passed to popen()",
  "cvss3_score": "7.8",
  "cvss3_scoring_vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
  "cvss_score": null,
  "cvss_scoring_vector": null,
  "package_state": null,
  "public_date": "2026-09-02T13:35:12Z",
  "resource_url": "https://access.redhat.com/hydra/rest/securitydata/cve/CVE-2026-84838.json",
  "severity": "moderate"
}
—
Cwe
cwe
Red HatCWE-78
receipt
Source
Red Hat
Its words
CWE-78
Read by
field:CWE
Said since
2026-09-29 09:44 UTC
Last answered
2026-10-02 18:04 UTC
Original
open at the source
What the source handed over
{
  "CVE": "CVE-2026-84838",
  "CWE": "CWE-78",
  "advisories": [],
  "affected_packages": [],
  "bugzilla": "2462222",
  "bugzilla_description": "rpm: Command injection in rpmuncompress via unescaped filenames passed to popen()",
  "cvss3_score": "7.8",
  "cvss3_scoring_vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
  "cvss_score": null,
  "cvss_scoring_vector": null,
  "package_state": null,
  "public_date": "2026-09-02T13:35:12Z",
  "resource_url": "https://access.redhat.com/hydra/rest/securitydata/cve/CVE-2026-84838.json",
  "severity": "moderate"
}
—
Severity
severity
Red Hatmoderate
A flaw that is harder to exploit, or whose impact is limited.
receipt
Source
Red Hat
Its words
moderate
Read by
field:severity
Said since
2026-09-29 09:44 UTC
Last answered
2026-10-02 18:04 UTC
Original
open at the source
What the source handed over
{
  "CVE": "CVE-2026-84838",
  "CWE": "CWE-78",
  "advisories": [],
  "affected_packages": [],
  "bugzilla": "2462222",
  "bugzilla_description": "rpm: Command injection in rpmuncompress via unescaped filenames passed to popen()",
  "cvss3_score": "7.8",
  "cvss3_scoring_vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
  "cvss_score": null,
  "cvss_scoring_vector": null,
  "package_state": null,
  "public_date": "2026-09-02T13:35:12Z",
  "resource_url": "https://access.redhat.com/hydra/rest/securitydata/cve/CVE-2026-84838.json",
  "severity": "moderate"
}
medium

vulnerability

rpm: Command injection in rpmuncompress via unescaped filenames passed to popen()
zetlyn/cve-redhat · 2026-09-02
cvss 7.8 cwe CWE-78 severity moderate source