{"id":"AZL-99372","summary":"CVE-2026-84838 affecting package rpm 4.18.2-1","details":"A flaw was found in rpmuncompress. This command injection vulnerability allows a local attacker to execute arbitrary commands. This occurs when rpmuncompress processes a specially crafted archive filename containing shell metacharacters, which are not properly escaped before being passed to shell command strings. Successful exploitation requires user interaction, where a user or automated workflow invokes rpmuncompress on the malicious file, leading to high impact on the confidentiality, integrity, and availability of data accessible to the invoking user.","modified":"2026-09-07T05:28:29Z","published":"2026-09-02T16:17:33Z","upstream":["CVE-2026-84838"],"references":[{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-84838"}],"affected":[{"package":{"name":"rpm","ecosystem":"Azure Linux:3","purl":"pkg:rpm/azure-linux/rpm"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"last_affected":"4.18.2-1"}]}],"database_specific":{"source":"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-99372.json"}}],"schema_version":"1.9.0"}