CVE-2021-20266
published 2021-04-30CVE-2021-20266: A flaw was found in RPM's hdrblobInit() in lib/header.c. This flaw allows an attacker who can modify the rpmdb to cause an out-of-bounds read. The highest…
PriorityP424medium4.9CVSS 3.1
AVNACLPRHUINSUCNINAH
EPSS
1.71%
74.7th percentile
A flaw was found in RPM's hdrblobInit() in lib/header.c. This flaw allows an attacker who can modify the rpmdb to cause an out-of-bounds read. The highest threat from this vulnerability is to system availability.
Affected
15 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | rpm | < rpm 4.16.1.2+dfsg1-1 (bookworm) | rpm 4.16.1.2+dfsg1-1 (bookworm) |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| msrc | cbl_mariner_1.0_arm | — | — |
| msrc | cbl_mariner_1.0_x64 | — | — |
| msrc | cm1_rpm_4.14.2-13_on_cbl_mariner_1.0 | — | — |
| rpm | rpm | < 4.16.1.3 | 4.16.1.3 |
| rpm | rpm | — | — |
| rpm | rpm | >= 0 < 4.16.1.2+dfsg1-1 | 4.16.1.2+dfsg1-1 |
| rpm | rpm | >= 0 < 4.16.1.2+dfsg1-1 | 4.16.1.2+dfsg1-1 |
| rpm | rpm | >= 0 < 4.16.1.2+dfsg1-1 | 4.16.1.2+dfsg1-1 |
| rpm | rpm | >= 0 < 4.16.1.2+dfsg1-1 | 4.16.1.2+dfsg1-1 |
| rpm | rpm | >= 0 < 4.12.0.1+dfsg1-3ubuntu0.1~esm1 | 4.12.0.1+dfsg1-3ubuntu0.1~esm1 |
| rpm | rpm | >= 0 < 4.14.1+dfsg1-2ubuntu0.1~esm1 | 4.14.1+dfsg1-2ubuntu0.1~esm1 |
| rpm | rpm | >= 0 < 4.14.2.1+dfsg1-1ubuntu0.1~esm1 | 4.14.2.1+dfsg1-1ubuntu0.1~esm1 |
CVSS provenance
nvdv3.14.9MEDIUMCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H
nvdv2.04.0MEDIUMAV:N/AC:L/Au:S/C:N/I:N/A:P
osv4.9MEDIUM
vendor_debian4.9MEDIUM
vendor_msrc4.9MEDIUM
vendor_redhat4.9MEDIUM
vendor_ubuntu4.9MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
RPM Package Manager vulnerabilities
vendor_ubuntu·2022-07-21·CVSS 4.9
CVE-2021-20266 [MEDIUM] RPM Package Manager vulnerabilities
Title: RPM Package Manager vulnerabilities
Summary: Several security issues were fixed in RPM Package Manager.
Demi M. Obenour discovered that RPM Package Manager incorrectly handled
certain files. An attacker could possibly use this issue to corrupt the
database and cause a denial of service. (CVE-2021-3421, CVE-2021-20271)
Demi M. Obenour discovered that RPM Package Manager incorrectly handled
memory when processing certain data from the database. An attacker could
possibly use this issue to cause a denial of service. This issue only
affects Ubuntu 18.04 ESM and Ubuntu 20.04 ESM. (CVE-2021-20266)
Instructions: In general, a standard system update will make all the necessary changes.
Microsoft
A flaw was found in RPM's hdrblobInit() in lib/header.c. This flaw allows an attacker who can modify the rpmdb to cause an out-of-bounds read. The highest threat from this vulnerability is to system a
vendor_msrc·2021-04-13·CVSS 4.9
CVE-2021-20266 [MEDIUM] CWE-125 A flaw was found in RPM's hdrblobInit() in lib/header.c. This flaw allows an attacker who can modify the rpmdb to cause an out-of-bounds read. The highest threat from this vulnerability is to system a
A flaw was found in RPM's hdrblobInit() in lib/header.c. This flaw allows an attacker who can modify the rpmdb to cause an out-of-bounds read. The highest threat from this vulnerability is to system availability.
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog post for more information. If impact to additional products is identified, we wil
Red Hat
rpm: missing length checks in hdrblobInit()
vendor_redhat·2021-03-11·CVSS 4.9
CVE-2021-20266 [MEDIUM] CWE-125 rpm: missing length checks in hdrblobInit()
rpm: missing length checks in hdrblobInit()
A flaw was found in RPM's hdrblobInit() in lib/header.c. This flaw allows an attacker who can modify the rpmdb to cause an out-of-bounds read. The highest threat from this vulnerability is to system availability.
A flaw was found in RPM’s hdrblobInit() in lib/header.c. This flaw allows an attacker who can modify the rpmdb to cause an out-of-bounds read. The highest threat from this vulnerability is to system availability.
Statement: In order to exploit this flaw with rpm tooling as shipped in Red Hat Enterprise Linux, an attacker would need to already have root access to modify the rpm database.
Mitigation: If using the headerCheck() and headerImport() APIs in your software, do not run them on headers from untrusted sources.
Package: rpm (Re
Debian
CVE-2021-20266: rpm - A flaw was found in RPM's hdrblobInit() in lib/header.c. This flaw allows an att...
vendor_debian·2021·CVSS 4.9
CVE-2021-20266 [MEDIUM] CVE-2021-20266: rpm - A flaw was found in RPM's hdrblobInit() in lib/header.c. This flaw allows an att...
A flaw was found in RPM's hdrblobInit() in lib/header.c. This flaw allows an attacker who can modify the rpmdb to cause an out-of-bounds read. The highest threat from this vulnerability is to system availability.
Scope: local
bookworm: resolved (fixed in 4.16.1.2+dfsg1-1)
bullseye: resolved (fixed in 4.16.1.2+dfsg1-1)
forky: resolved (fixed in 4.16.1.2+dfsg1-1)
sid: resolved (fixed in 4.16.1.2+dfsg1-1)
trixie: resolved (fixed in 4.16.1.2+dfsg1-1)
OSV
rpm vulnerabilities
osv·2022-07-21·CVSS 4.9
CVE-2021-3421 [MEDIUM] rpm vulnerabilities
rpm vulnerabilities
Demi M. Obenour discovered that RPM Package Manager incorrectly handled
certain files. An attacker could possibly use this issue to corrupt the
database and cause a denial of service. (CVE-2021-3421, CVE-2021-20271)
Demi M. Obenour discovered that RPM Package Manager incorrectly handled
memory when processing certain data from the database. An attacker could
possibly use this issue to cause a denial of service. This issue only
affects Ubuntu 18.04 ESM and Ubuntu 20.04 ESM. (CVE-2021-20266)
GHSA
GHSA-8vf3-43pf-v3cq: A flaw was found in RPM's hdrblobInit() in lib/header
ghsa_unreviewed·2022-05-24
CVE-2021-20266 [MEDIUM] CWE-125 GHSA-8vf3-43pf-v3cq: A flaw was found in RPM's hdrblobInit() in lib/header
A flaw was found in RPM's hdrblobInit() in lib/header.c. This flaw allows an attacker who can modify the rpmdb to cause an out-of-bounds read. The highest threat from this vulnerability is to system availability.
OSV
CVE-2021-20266: A flaw was found in RPM's hdrblobInit() in lib/header
osv·2021-04-30·CVSS 4.9
CVE-2021-20266 [MEDIUM] CVE-2021-20266: A flaw was found in RPM's hdrblobInit() in lib/header
A flaw was found in RPM's hdrblobInit() in lib/header.c. This flaw allows an attacker who can modify the rpmdb to cause an out-of-bounds read. The highest threat from this vulnerability is to system availability.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://bugzilla.redhat.com/show_bug.cgi?id=1927741https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/TMGXO3W6DHPO62GJ4VVF5DEUX5DRUR5K/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/VHRPNBCRPDJHHQE3MBPSZK4H7X2IM7AC/https://security.gentoo.org/glsa/202107-43https://bugzilla.redhat.com/show_bug.cgi?id=1927741https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/TMGXO3W6DHPO62GJ4VVF5DEUX5DRUR5K/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/VHRPNBCRPDJHHQE3MBPSZK4H7X2IM7AC/https://security.gentoo.org/glsa/202107-43
2021-04-30
Published