PT-2026-22490 · Unknown · Rust-Rpm-Sequoia

Yashashree Gund

·

Published

2026-01-01

·

Updated

2026-05-01

·

CVE-2026-2625

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions rust-rpm-sequoia (affected versions not specified)
Description A flaw exists in rust-rpm-sequoia that allows an attacker to cause an application-level denial of service. This occurs when a specially crafted Red Hat Package Manager (RPM) file is provided. The vulnerability is triggered during RPM signature verification, specifically within the OpenPGP signature parsing code, leading to the unconditional termination of the rpm process. This prevents the system from processing RPM files for signature verification.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

DoS

Improper Verification of Cryptographic Signature

Weakness Enumeration

Related Identifiers

CVE-2026-2625
ECHO-2654-D857-4161
RHSA-2026:12682

Affected Products

Rust-Rpm-Sequoia