Fedora Account System
Red Hat Associate
Red Hat Customer
A heap-based buffer overflow write was found in RPM's hex2binv() function (lib/rpmfi.cc). In a crafted, unsigned RPM v4 package, the RPMTAG_FILESIGNATURES tag in the main header is declared with type RPM_I18NSTRING_TYPE (9) instead of its intended RPM_STRING_ARRAY_TYPE (8). This mismatch causes headerGet() to route the tag through copyI18NEntry(), which sets the tag's count and data but never sets its size field. hex2binv() sizes its output buffer from that (unset, and therefore zero) size, allocating only one byte, while its decode loop then writes half the length of the attacker-controlled hex string into that one-byte buffer -- an overflow of arbitrary, attacker-chosen length past the allocation. The flaw is reachable by any command or library caller that populates rpmfi/rpmfiles data from an untrusted package's file signatures, such as `rpm -qlvp`, `rpm2cpio`, or `rpm2archive`. No package signature is required, since these tools do not validate package signatures by default. The issue was confirmed against the shipped rpm binary on Fedora Linux 44 (rpm-6.0.2): Valgrind reports an invalid one-byte write immediately past a one-byte heap allocation inside rpmfilesNew() (the inlined caller of hex2binv()), and a larger crafted payload reliably crashes the process with SIGSEGV.