RPM is the package manager at the foundation of Red Hat–based Linux distributions and related systems, with a relatively narrow product scope that masks its ubiquity across enterprise and embedded Linux deployments. The vendor's vulnerability footprint concentrates in the core RPM package manager, its successor DNF5, and supporting libraries such as libdnf and libcomps, all of which handle package installation, verification, and code execution at a privileged level. Recurring weakness classes reflect the security-critical nature of this role: link-following and path-traversal flaws that can misdirect file operations, improper input validation in package metadata parsing, cryptographic signature verification bypasses, and code-injection vectors that arise from the integration of untrusted package content. Defenders should prioritize patch cycles for package manager and related library updates, as flaws in this tier can undermine the integrity of the entire system; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Rpm over time
Signals from CVEs in this vendor scope (26 CVEs).
26 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-10897HIGH A directory traversal issue was found in reposync, a part of yum-utils, where reposync fails to sanitize paths in remote repository configuration files. If an attacker controls a r | Aug 1, 2018 | 8.1 | 29 | NO | NO |
CVE-2011-3378HIGH RPM 4.4.x through 4.9.x, probably before 4.9.1.2, allows remote attackers to cause a denial of service (memory corruption) and possibly execute arbitrary code via an rpm package wi | Dec 24, 2011 | 9.3 | 29 | NO | NO |
CVE-2019-3817HIGH A use-after-free flaw has been discovered in libcomps before version 0.1.10 in the way ObjMRTrees are merged. An attacker, who is able to make an application read a crafted comps X | Mar 27, 2019 | 8.8 | 27 | NO | NO |
CVE-2014-8118HIGH Integer overflow in RPM 4.12 and earlier allows remote attackers to execute arbitrary code via a crafted CPIO header in the payload section of an RPM file, which triggers a stack-b | Dec 16, 2014 | 10.0 | 27 | NO | NO |
CVE-2024-1929HIGH Local Root Exploit via Configuration Dictionary in dnf5daemon-server before 5.1.17 allows a malicious user to impact Confidentiality and Integrity via Configuration Dictionary.
T | May 8, 2024 | 8.4 | 26 | NO | NO |
CVE-2017-7500HIGH It was found that rpm did not properly handle RPM installations when a destination path was a symbolic link to a directory, possibly changing ownership and permissions of an arbitr | Aug 13, 2018 | 7.8 | 26 | NO | NO |
CVE-2017-7501HIGH It was found that versions of rpm before 4.13.0.2 use temporary files with predictable names when installing an RPM. An attacker with ability to write in a directory where files wi | Nov 22, 2017 | 7.8 | 26 | NO | NO |
CVE-2021-3445HIGH A flaw was found in libdnf's signature verification functionality in versions before 0.60.1. This flaw allows an attacker to achieve code execution if they can alter the header inf | May 19, 2021 | 7.5 | 24 | NO | NO |
CVE-2021-20271HIGH A flaw was found in RPM's signature check functionality when reading a package file. This flaw allows an attacker who can convince a victim to install a seemingly verifiable packag | Mar 26, 2021 | 7.0 | 24 | NO | NO |
CVE-2021-35939MEDIUM It was found that the fix for CVE-2017-7500 and CVE-2017-7501 was incomplete: the check was only implemented for the parent directory of the file to be created. A local unprivilege | Aug 26, 2022 | 6.7 | 23 | NO | NO |
Signals from CVEs in this vendor scope (26 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Rpm.
Media articles that mention a CVE ID that affects a product developed by Rpm — matched by CVE ID, not by vendor name.