Bug 2478408 (CVE-2026-84837)
| Summary: | CVE-2026-84837 rpm: Command Injection in `rpmbuild -t*` (`getTarSpec`) via Unescaped Tarball Path | ||
|---|---|---|---|
| Product: | [Other] Security Response | Reporter: | OSIDB Bzimport <bzimport> |
| Component: | vulnerability | Assignee: | Product Security DevOps Team <prodsec-dev> |
| Status: | NEW --- | QA Contact: | |
| Severity: | medium | Docs Contact: | |
| Priority: | medium | ||
| Version: | unspecified | CC: | rhel-process-autobot, security-response-team, watson-tool-maintainers |
| Target Milestone: | --- | Keywords: | Security |
| Target Release: | --- | ||
| Hardware: | All | ||
| OS: | Linux | ||
| Whiteboard: | |||
| Fixed In Version: | Doc Type: | --- | |
| Doc Text: |
A flaw was found in rpm. An attacker can exploit a command injection vulnerability by influencing the path or filename of a tarball processed by `rpmbuild -t*` to include shell metacharacters. This is particularly relevant in automated build or continuous integration (CI) workflows that ingest externally supplied artifact names. Successful exploitation allows for arbitrary command execution with the privileges of the build user, which could lead to information disclosure or disruption of the build environment.
|
Story Points: | --- |
| Clone Of: | Environment: | ||
| Last Closed: | Type: | --- | |
| Regression: | --- | Mount Type: | --- |
| Documentation: | --- | CRM: | |
| Verified Versions: | Category: | --- | |
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
| Cloudforms Team: | --- | Target Upstream Version: | |
| Embargoed: | |||
| Bug Depends On: | 2527528 | ||
| Bug Blocks: | |||
AI_ONLY_REPORT package: rpm-4.19.1.1-23.el10 ------ Summary: Command Injection in `rpmbuild -t*` (`getTarSpec`) via Unescaped Tarball Path: attacker-influenced tarball paths or filenames can inject shell syntax into tarbuild command construction and execute unintended commands as the build user. Requirements to exploit: An attacker must be able to cause `rpmbuild -t*` to process a tarball whose path or filename contains shell metacharacters. This is most relevant to automated build or CI workflows that ingest externally supplied artifact names; environments that only build trusted, locally named tarballs are not exposed in the same way. Component affected: `rpm-4.19.1.1-23.el10`, `tools/rpmbuild.c:getTarSpec()`, and the `%{uncompress:...}` expansion path used by `rpmbuild -t*` Version affected: `rpm-4.19.1.1-23.el10`, in `rpmbuild -t*` tarbuild workflows that process attacker-influenced tarball paths or filenames Patch available: no released package fix established; proposed patch included below Version fixed: unknown Upstream coordination: Not notified. CVSS: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H - 7.8 (HIGH) AV:L - The vulnerable command executes on the local build host when `rpmbuild -t*` processes a tarball path or filename. AC:L - No special race or unusual condition is needed once the attacker can influence that path or filename. PR:N - The flaw itself does not require prior privileges in `rpmbuild`; the attack condition is control of the build input name or path. UI:N - In automated build pipelines, the vulnerable flow can be reached non-interactively once the maliciously named artifact is consumed. S:U - Code execution occurs in the same security scope as the `rpmbuild` process. C:H - Successful injection can expose data available to the build user. I:H - Successful injection allows arbitrary command execution in the build user's context. A:H - Successful injection can disrupt or destroy the build environment or its outputs. Impact: Moderate. This issue can lead to arbitrary command execution in the build user's context, but exploitation depends on a specific tarbuild workflow that accepts attacker-influenced tarball paths or filenames. Under Red Hat's severity guidance, that makes it less broadly exposed than a typical easy code-execution flaw and better aligned with Moderate than Important. Embargo: no Reason: The issue is real but workflow-dependent, requires attacker influence over the tarball path or filename in `rpmbuild -t*`, and does not appear to represent an easily wormable or default remote compromise path. Acknowledgement: Aisle Research Vulnerability Details: In `rpmbuild -t*` tarbuild modes, `getTarSpec()` constructs a shell command string from the tarball path and runs it with `popen()`. The tarball path is taken from positional CLI input, and `%{uncompress:...}` appends that argument without shell escaping. As a result, shell metacharacters in the tarball path or filename can change the command executed by the build process. ```c cmd = rpmExpand("%{uncompress: ", arg, "} | ", "%{__tar} xOvof - --wildcards ", *spec, " 2>&1 > ", specFile, NULL); if (!(fp = popen(cmd, "r"))) { rpmlog(RPMLOG_ERR, _("Failed to open tar pipe: %m\n")); } ``` ```c if (*argv[1]) { expandMacro(mb, "%__rpmuncompress ", 0); mbAppendStr(mb, argv[1]); } ``` Based on the available evidence, the practical impact is unintended command execution with the privileges of the user or automation account running `rpmbuild`. The issue appears confined to tarbuild modes and to environments where the tarball path or filename can be attacker-influenced. Steps to reproduce: 1. Prepare a valid source tarball containing exactly one `.spec` file, for example `hello-1.0.tar.gz`. 2. Rename it to include shell syntax: `mv hello-1.0.tar.gz "hello;touch /tmp/rpmbuild_injected;#.tar.gz"` 3. Invoke tarbuild mode on the renamed file: `rpmbuild -ta "hello;touch /tmp/rpmbuild_injected;#.tar.gz"` 4. Verify the injected side effect: `test -f /tmp/rpmbuild_injected && echo INJECTION_CONFIRMED` Expected result: `/tmp/rpmbuild_injected` is created, showing that shell syntax in the tarball path or filename was interpreted before the intended tar extraction command completed. Mitigation: Until a fix is available, avoid running `rpmbuild -t*` on tarballs whose path or filename can be influenced by untrusted input. In build automation, stage tarballs into a trusted local directory and normalize or reject names containing shell metacharacters before invoking `rpmbuild`. Proposed Fix: The smallest targeted mitigation is to shell-escape the tarball path, the matched spec name, and the temporary output file before building the `popen()` command string. A more robust long-term fix would avoid shell command composition entirely and use direct `exec`-style argument vectors. ```diff diff --git a/tools/rpmbuild.c b/tools/rpmbuild.c @@ -385,9 +385,9 @@ static char * getTarSpec(const char *arg) cmd = rpmExpand("%{uncompress: ", arg, "} | ", "%{__tar} xOvof - --wildcards ", *spec, " 2>&1 > ", specFile, NULL); + cmd = rpmExpand("%{uncompress:%{shescape:", arg, "}} | ", + "%{__tar} xOvof - --wildcards %{shescape:", *spec, "}", + " 2>&1 > %{shescape:", specFile, "}", NULL); ``` ------ This report was generated using AI technology. Always review AI-generated content prior to use