Import Source
https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-99372.json
JSON Data
https://api.osv.dev/v1/vulns/AZL-99372
Upstream
  • CVE-2026-84838
Published
2026-09-02T16:17:33Z
Modified
2026-09-07T05:28:29Z
Summary
CVE-2026-84838 affecting package rpm 4.18.2-1
Details

A flaw was found in rpmuncompress. This command injection vulnerability allows a local attacker to execute arbitrary commands. This occurs when rpmuncompress processes a specially crafted archive filename containing shell metacharacters, which are not properly escaped before being passed to shell command strings. Successful exploitation requires user interaction, where a user or automated workflow invokes rpmuncompress on the malicious file, leading to high impact on the confidentiality, integrity, and availability of data accessible to the invoking user.

References

Affected packages

Azure Linux:3 / rpm

Package

Name
rpm
Purl
pkg:rpm/azure-linux/rpm

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Last affected
4.18.2-1

Database specific

source
"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-99372.json"