Bug 2527528

Summary: CVE-2026-84837 rpm: Command Injection in `rpmbuild -t*` (`getTarSpec`) via Unescaped Tarball Path [fedora-all]
Product: [Fedora] Fedora Reporter: Vladimir Vasilev <vvasilev>
Component: rpmAssignee: Panu Matilainen <pmatilai>
Status: NEW --- QA Contact: Fedora Extras Quality Assurance <extras-qa>
Severity: medium Docs Contact:
Priority: medium    
Version: rawhideCC: igor.raits, mdomonko, packaging-team-maint, pmatilai
Target Milestone: ---Keywords: Security, SecurityTracking
Target Release: ---Flags: fedora-admin-xmlrpc: mirror+
Hardware: Unspecified   
OS: Unspecified   
Whiteboard: {"flaws": ["4436ce3b-2ff0-4e3c-ada2-6d36d4df7f75"]}
Fixed In Version: Doc Type: ---
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On:    
Bug Blocks: 2478408    

Description Vladimir Vasilev 2026-09-02 15:14:29 UTC
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.

AI_ONLY_REPORT
package: rpm-4.19.1.1-23.el10
------
Summary: Command Injection in `rpmbuild -t*` (`getTarSpec`) via Unescaped  
Tarball Path: attacker-influenced tarball paths or filenames can inject  
shell syntax into tarbuild command construction and execute unintended  
commands as the build user.
Requirements to exploit: An attacker must be able to cause `rpmbuild -t*`  
to process a tarball whose path or filename contains shell metacharacters.  
This is most relevant to automated build or CI workflows that ingest  
externally supplied artifact names; environments that only build trusted,  
locally named tarballs are not exposed in the same way.
Component affected: `rpm-4.19.1.1-23.el10`,  
`tools/rpmbuild.c:getTarSpec()`, and the `%{uncompress:...}` expansion path  
used by `rpmbuild -t*`
Version affected: `rpm-4.19.1.1-23.el10`, in `rpmbuild -t*` tarbuild  
workflows that process attacker-influenced tarball paths or filenames
Patch available: no released package fix established; proposed patch  
included below
Version fixed: unknown
Upstream coordination: Not notified.
CVSS: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H - 7.8 (HIGH)
AV:L - The vulnerable command executes on the local build host when  
`rpmbuild -t*` processes a tarball path or filename.
AC:L - No special race or unusual condition is needed once the attacker  
can influence that path or filename.
PR:N - The flaw itself does not require prior privileges in `rpmbuild`;  
the attack condition is control of the build input name or path.
UI:N - In automated build pipelines, the vulnerable flow can be reached  
non-interactively once the maliciously named artifact is consumed.
S:U - Code execution occurs in the same security scope as the `rpmbuild`  
process.
C:H - Successful injection can expose data available to the build user.
I:H - Successful injection allows arbitrary command execution in the  
build user's context.
A:H - Successful injection can disrupt or destroy the build environment  
or its outputs.
Impact: Moderate. This issue can lead to arbitrary command execution in the  
build user's context, but exploitation depends on a specific tarbuild  
workflow that accepts attacker-influenced tarball paths or filenames. Under  
Red Hat's severity guidance, that makes it less broadly exposed than a  
typical easy code-execution flaw and better aligned with Moderate than  
Important.
Embargo: no
Reason: The issue is real but workflow-dependent, requires attacker  
influence over the tarball path or filename in `rpmbuild -t*`, and does not  
appear to represent an easily wormable or default remote compromise path.
Acknowledgement: Aisle Research
Vulnerability Details: In `rpmbuild -t*` tarbuild modes, `getTarSpec()`  
constructs a shell command string from the tarball path and runs it with  
`popen()`. The tarball path is taken from positional CLI input, and  
`%{uncompress:...}` appends that argument without shell escaping. As a  
result, shell metacharacters in the tarball path or filename can change the  
command executed by the build process.
```c
cmd = rpmExpand("%{uncompress: ", arg, "} | ",
"%{__tar} xOvof - --wildcards ", *spec,
" 2>&1 > ", specFile, NULL);
if (!(fp = popen(cmd, "r"))) {
rpmlog(RPMLOG_ERR, _("Failed to open tar pipe: %m\n"));
}
```
```c
if (*argv[1]) {
expandMacro(mb, "%__rpmuncompress ", 0);
mbAppendStr(mb, argv[1]);
}
```
Based on the available evidence, the practical impact is unintended command  
execution with the privileges of the user or automation account running  
`rpmbuild`. The issue appears confined to tarbuild modes and to  
environments where the tarball path or filename can be attacker-influenced.
Steps to reproduce:
1. Prepare a valid source tarball containing exactly one `.spec` file, for  
example `hello-1.0.tar.gz`.
2. Rename it to include shell syntax: `mv hello-1.0.tar.gz "hello;touch  
/tmp/rpmbuild_injected;#.tar.gz"`
3. Invoke tarbuild mode on the renamed file: `rpmbuild -ta "hello;touch  
/tmp/rpmbuild_injected;#.tar.gz"`
4. Verify the injected side effect: `test -f /tmp/rpmbuild_injected && echo  
INJECTION_CONFIRMED`
Expected result: `/tmp/rpmbuild_injected` is created, showing that shell  
syntax in the tarball path or filename was interpreted before the intended  
tar extraction command completed.
Mitigation: Until a fix is available, avoid running `rpmbuild -t*` on  
tarballs whose path or filename can be influenced by untrusted input. In  
build automation, stage tarballs into a trusted local directory and  
normalize or reject names containing shell metacharacters before invoking  
`rpmbuild`.
Proposed Fix: The smallest targeted mitigation is to shell-escape the  
tarball path, the matched spec name, and the temporary output file before  
building the `popen()` command string. A more robust long-term fix would  
avoid shell command composition entirely and use direct `exec`-style  
argument vectors.
```diff
diff --git a/tools/rpmbuild.c b/tools/rpmbuild.c
@@ -385,9 +385,9 @@ static char * getTarSpec(const char *arg)
      cmd = rpmExpand("%{uncompress: ", arg, "} | ",

                      "%{__tar} xOvof - --wildcards ", *spec,

                      " 2>&1 > ", specFile, NULL);
+       cmd = rpmExpand("%{uncompress:%{shescape:", arg, "}} | ",
+                       "%{__tar} xOvof - --wildcards %{shescape:",  
*spec, "}",
+                       " 2>&1 > %{shescape:", specFile, "}", NULL);
```


------
This report was generated using AI technology. Always review AI-generated  
content prior to use