Skip to content
Fedora 43 RPM Heap Overflow and Command Injection Vulnerability Advisory

Fedora 43 RPM Heap Overflow and Command Injection Vulnerability Advisory

Linuxsecurity LinuxSecurity Advisories July 28, 2026

Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges ×

The RPM Package Manager (RPM) is a powerful command line driven

package management system capable of installing, uninstalling,

verifying, querying, and updating software packages. Each software

package consists of an archive of files along with information

the package like its version, a description, etc.

Rebase to 6.0.2 (

* Thu Jul 16 2026 Michal Domonkos - 6.0.2-1 - Rebase to 6.0.2 (

* Thu Jul 16 2026 Michal Domonkos - 6.0.2-1 - Rebase to 6.0.2 (

[ 1 ] Bug #2482483 - CVE-2026-44605 rpm: heap buffer overflow in NDB slot table parsing [fedora-43] [ 2 ] Bug #2482484 - CVE-2026-44604 rpm: Command injection in rpmuncompress doUntar() via unescaped archive top-level directory name in popen() shell command [fedora-43]

This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-a9f0d5370e' at the command line. For more information, refer to the dnf documentation available at

Get the latest Linux and open source security news straight to your inbox.