Metrics
Affected Vendors & Products
No advisories yet.
Solution
No solution given by the vendor.
Workaround
Avoid processing untrusted or attacker-controlled RPM files with rpm -Kv or rpm --checksig. Use isolated environments or additional validation layers when handling untrusted RPM artifacts.
Fri, 03 Apr 2026 19:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | No description is available for this CVE. | A flaw was found in rust-rpm-sequoia. An attacker can exploit this vulnerability by providing a specially crafted Red Hat Package Manager (RPM) file. During the RPM signature verification process, this crafted file can trigger an error in the OpenPGP signature parsing code, leading to an unconditional termination of the rpm process. This issue results in an application level denial of service, making the system unable to process RPM files for signature verification. |
| Title | rust-rpm-sequoia: rust-rpm-sequoia: Denial of Service via crafted RPM file during signature verification | Rust-rpm-sequoia: rust-rpm-sequoia: denial of service via crafted rpm file during signature verification |
| First Time appeared |
Redhat
Redhat enterprise Linux Redhat hummingbird |
|
| CPEs | cpe:/a:redhat:hummingbird:1 cpe:/o:redhat:enterprise_linux:10 cpe:/o:redhat:enterprise_linux:9 |
|
| Vendors & Products |
Redhat
Redhat enterprise Linux Redhat hummingbird |
|
| References |
|
Wed, 18 Feb 2026 11:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Rust-rpm-sequoia
Rust-rpm-sequoia rust-rpm-sequoia |
|
| Vendors & Products |
Rust-rpm-sequoia
Rust-rpm-sequoia rust-rpm-sequoia |
Wed, 18 Feb 2026 00:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | No description is available for this CVE. | |
| Title | rust-rpm-sequoia: rust-rpm-sequoia: Denial of Service via crafted RPM file during signature verification | |
| Weaknesses | CWE-347 | |
| References |
| |
| Metrics |
threat_severity
|
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2026-04-03T18:38:09.601Z
Reserved: 2026-02-17T13:16:29.204Z
Link: CVE-2026-2625
No data.
Status : Received
Published: 2026-04-03T19:17:22.340
Modified: 2026-04-03T19:17:22.340
Link: CVE-2026-2625
OpenCVE Enrichment
Updated: 2026-02-18T10:44:28Z