Back Linuxsecurity Fedora 43 RPM Heap Overflow and Command Injection Vulnerability Advisory
Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges ×
The RPM Package Manager (RPM) is a powerful command line driven
package management system capable of installing, uninstalling,
verifying, querying, and updating software packages. Each software
package consists of an archive of files along with information
the package like its version, a description, etc.
Rebase to 6.0.2 (
* Thu Jul 16 2026 Michal Domonkos - 6.0.2-1 - Rebase to 6.0.2 (
* Thu Jul 16 2026 Michal Domonkos - 6.0.2-1 - Rebase to 6.0.2 (
[ 1 ] Bug #2482483 - CVE-2026-44605 rpm: heap buffer overflow in NDB slot table parsing [fedora-43] [ 2 ] Bug #2482484 - CVE-2026-44604 rpm: Command injection in rpmuncompress doUntar() via unescaped archive top-level directory name in popen() shell command [fedora-43]
This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-a9f0d5370e' at the command line. For more information, refer to the dnf documentation available at
Get the latest Linux and open source security news straight to your inbox.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
