A flaw was found in rust-rpm-sequoia. An attacker can exploit this vulnerability by providing a specially crafted Red Hat Package Manager (RPM) file. During the RPM signature verification process, this crafted file can trigger an error in the OpenPGP signature parsing code, leading to an unconditional termination of the rpm process. This issue results in an application level denial of service, making the system unable to process RPM files for signature verification.
History

Fri, 03 Apr 2026 19:00:00 +0000

Type Values Removed Values Added
Description No description is available for this CVE. A flaw was found in rust-rpm-sequoia. An attacker can exploit this vulnerability by providing a specially crafted Red Hat Package Manager (RPM) file. During the RPM signature verification process, this crafted file can trigger an error in the OpenPGP signature parsing code, leading to an unconditional termination of the rpm process. This issue results in an application level denial of service, making the system unable to process RPM files for signature verification.
Title rust-rpm-sequoia: rust-rpm-sequoia: Denial of Service via crafted RPM file during signature verification Rust-rpm-sequoia: rust-rpm-sequoia: denial of service via crafted rpm file during signature verification
First Time appeared Redhat
Redhat enterprise Linux
Redhat hummingbird
CPEs cpe:/a:redhat:hummingbird:1
cpe:/o:redhat:enterprise_linux:10
cpe:/o:redhat:enterprise_linux:9
Vendors & Products Redhat
Redhat enterprise Linux
Redhat hummingbird
References

Wed, 18 Feb 2026 11:00:00 +0000

Type Values Removed Values Added
First Time appeared Rust-rpm-sequoia
Rust-rpm-sequoia rust-rpm-sequoia
Vendors & Products Rust-rpm-sequoia
Rust-rpm-sequoia rust-rpm-sequoia

Wed, 18 Feb 2026 00:15:00 +0000

Type Values Removed Values Added
Description No description is available for this CVE.
Title rust-rpm-sequoia: rust-rpm-sequoia: Denial of Service via crafted RPM file during signature verification
Weaknesses CWE-347
References
Metrics threat_severity

None

cvssV3_1

{'score': 4.0, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L'}

threat_severity

Moderate


cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published:

Updated: 2026-04-03T18:38:09.601Z

Reserved: 2026-02-17T13:16:29.204Z

Link: CVE-2026-2625

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-04-03T19:17:22.340

Modified: 2026-04-03T19:17:22.340

Link: CVE-2026-2625

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-02-17T12:34:00Z

Links: CVE-2026-2625 - Bugzilla