cbcvebase.
CVE-2021-20271
published 2021-03-26

CVE-2021-20271: A flaw was found in RPM's signature check functionality when reading a package file. This flaw allows an attacker who can convince a victim to install a…

PriorityP430high7CVSS 3.1
AVLACHPRNUIRSUCHIHAH
EPSS
0.83%
53.4th percentile
A flaw was found in RPM's signature check functionality when reading a package file. This flaw allows an attacker who can convince a victim to install a seemingly verifiable package, whose signature header was modified, to cause RPM database corruption and execute code. The highest threat from this vulnerability is to data integrity, confidentiality, and system availability.

Affected

36 ranges· showing 25
VendorProductVersion rangeFixed in
debianrpm< rpm 4.16.1.2+dfsg1-1 (bookworm)rpm 4.16.1.2+dfsg1-1 (bookworm)
fedoraprojectfedora
fedoraprojectfedora
fedoraprojectfedora
msrcpython-rpm-4.14.2-11.cm1.aarch64.rpm_on_cbl_mariner_1.0_arm
msrcpython-rpm-4.14.2-11.cm1.x86_64.rpm_on_cbl_mariner_1.0_x64
msrcpython3-rpm-4.14.2-11.cm1.aarch64.rpm_on_cbl_mariner_1.0_arm
msrcpython3-rpm-4.14.2-11.cm1.x86_64.rpm_on_cbl_mariner_1.0_x64
msrcrpm-4.14.2-11.cm1.aarch64.rpm_on_cbl_mariner_1.0_arm
msrcrpm-4.14.2-11.cm1.x86_64.rpm_on_cbl_mariner_1.0_x64
msrcrpm-build-4.14.2-11.cm1.aarch64.rpm_on_cbl_mariner_1.0_arm
msrcrpm-build-4.14.2-11.cm1.x86_64.rpm_on_cbl_mariner_1.0_x64
msrcrpm-build-libs-4.14.2-11.cm1.aarch64.rpm_on_cbl_mariner_1.0_arm
msrcrpm-build-libs-4.14.2-11.cm1.x86_64.rpm_on_cbl_mariner_1.0_x64
msrcrpm-debuginfo-4.14.2-11.cm1.aarch64.rpm_on_cbl_mariner_1.0_arm
msrcrpm-debuginfo-4.14.2-11.cm1.x86_64.rpm_on_cbl_mariner_1.0_x64
msrcrpm-devel-4.14.2-11.cm1.aarch64.rpm_on_cbl_mariner_1.0_arm
msrcrpm-devel-4.14.2-11.cm1.x86_64.rpm_on_cbl_mariner_1.0_x64
msrcrpm-lang-4.14.2-11.cm1.aarch64.rpm_on_cbl_mariner_1.0_arm
msrcrpm-lang-4.14.2-11.cm1.x86_64.rpm_on_cbl_mariner_1.0_x64
msrcrpm-libs-4.14.2-11.cm1.aarch64.rpm_on_cbl_mariner_1.0_arm
msrcrpm-libs-4.14.2-11.cm1.x86_64.rpm_on_cbl_mariner_1.0_x64
redhatenterprise_linux
rpmrpm
rpmrpm

CVSS provenance

nvdv3.17.0HIGHCVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.05.1MEDIUMAV:N/AC:H/Au:N/C:P/I:P/A:P
osv7.0HIGH
vendor_debian7.0HIGH
vendor_msrc7.0HIGH
vendor_redhat7.0HIGH
vendor_ubuntu4.9MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.