Arbitrary Code Injection Affecting rpm-build package, versions *


Severity

Recommended
medium

Based on CentOS security rating.

Threat Intelligence

EPSS
0.14% (4th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-CENTOS6-RPMBUILD-19371140
  • published27 Aug 2026
  • disclosed24 Aug 2026

Introduced: 24 Aug 2026

NewCVE-2026-78367  (opens in a new tab)
CWE-94  (opens in a new tab)

How to fix?

There is no fixed version for Centos:6 rpm-build.

NVD Description

Note: Versions mentioned in the description apply only to the upstream rpm-build package and not the rpm-build package as distributed by Centos. See How to fix? for Centos:6 relevant fixed versions and status.

A vulnerability was found in RPM's rpmbuild tarball processing. When processing a crafted source archive, the getTarSpec() function in tools/rpmbuild.cc passes an attacker-controlled tar archive member name to rpmExpand() as part of a %{basename:...} macro expression. A specially crafted .spec member name can therefore inject RPM macros, including Lua expressions, resulting in arbitrary code execution with the privileges of the user running rpmbuild. This can be exploited when a victim or automated build system processes an attacker-controlled source tarball using rpmbuild tarball mode (such as -ts, -ta, or -tb).

CVSS Base Scores

version 3.1