A flaw was found in rust-rpm-sequoia. An attacker can exploit this vulnerability by providing a specially crafted Red Hat Package Manager (RPM) file. During the RPM signature verification process, this crafted file can trigger an error in the OpenPGP signature parsing code, leading to an unconditional termination of the rpm process. This issue results in an application level denial of service, making the system unable to process RPM files for signature verification.
Metrics
Affected Vendors & Products
References
History
Fri, 03 Apr 2026 19:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | No description is available for this CVE. | A flaw was found in rust-rpm-sequoia. An attacker can exploit this vulnerability by providing a specially crafted Red Hat Package Manager (RPM) file. During the RPM signature verification process, this crafted file can trigger an error in the OpenPGP signature parsing code, leading to an unconditional termination of the rpm process. This issue results in an application level denial of service, making the system unable to process RPM files for signature verification. |
| Title | rust-rpm-sequoia: rust-rpm-sequoia: Denial of Service via crafted RPM file during signature verification | Rust-rpm-sequoia: rust-rpm-sequoia: denial of service via crafted rpm file during signature verification |
| First Time appeared |
Redhat
Redhat enterprise Linux Redhat hummingbird |
|
| CPEs | cpe:/a:redhat:hummingbird:1 cpe:/o:redhat:enterprise_linux:10 cpe:/o:redhat:enterprise_linux:9 |
|
| Vendors & Products |
Redhat
Redhat enterprise Linux Redhat hummingbird |
|
| References |
|
Wed, 18 Feb 2026 11:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Rust-rpm-sequoia
Rust-rpm-sequoia rust-rpm-sequoia |
|
| Vendors & Products |
Rust-rpm-sequoia
Rust-rpm-sequoia rust-rpm-sequoia |
Wed, 18 Feb 2026 00:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | No description is available for this CVE. | |
| Title | rust-rpm-sequoia: rust-rpm-sequoia: Denial of Service via crafted RPM file during signature verification | |
| Weaknesses | CWE-347 | |
| References |
| |
| Metrics |
threat_severity
|
cvssV3_1
|
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2026-04-03T18:38:09.601Z
Reserved: 2026-02-17T13:16:29.204Z
Link: CVE-2026-2625
No data.
Status : Received
Published: 2026-04-03T19:17:22.340
Modified: 2026-04-03T19:17:22.340
Link: CVE-2026-2625