Import Source
https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-99369.json
JSON Data
https://api.osv.dev/v1/vulns/AZL-99369
Upstream
  • CVE-2026-84233
Published
2026-09-01T15:17:43Z
Modified
2026-09-05T14:17:01.909140423Z
Summary
CVE-2026-84233 affecting package rpm 4.18.2-1
Details

A flaw was found in rpm. A local attacker could supply a specially crafted .gem filename containing RPM macro syntax. When a user or automated workflow invokes rpmuncompress -x on this file, the macro expansion occurs during command construction. This allows the attacker to execute arbitrary commands with the privileges of the invoking account, leading to a compromise of confidentiality, integrity, and availability.

References

Affected packages

Azure Linux:3 / rpm

Package

Name
rpm
Purl
pkg:rpm/azure-linux/rpm

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Last affected
4.18.2-1

Database specific

source
"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-99369.json"