A flaw was found in RPM's signature check functionality when reading a package file. This flaw allows an attacker who can convince a victim to install a seemingly verifiable package, whose signature header was modified, to cause RPM database corruption and execute code. The highest threat from this vulnerability is to data integrity, confidentiality, and system availability.
Conclusion & alert: CVE-2021-20271 is rated Moderate Risk (40.9/100): CVSS High severity, with low exploitation likelihood (EPSS 0.15%). Mandatory action: Review affected assets and schedule remediation.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2025-12-13 | 0.15% | 0.15% | +0.01% |
| 2 | 2025-11-21 | 0.20% | 0.15% | -0.05% |
| 3 | 2025-11-18 | — | 0.20% | — |
Full EPSS history (16 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 7.0 | 3.1 | HIGH |
|
1.0 | 5.9 | [email protected] |
| 5.1 | 2.0 | MEDIUM |
|
4.9 | 6.4 | [email protected] |
| vendor | priority | summary | link |
|---|---|---|---|
alpine
|
high | CVE-2021-20271: 1 source package rows (rpm); 32 state rows across 8 repos (3.17-community, 3.18-community, 3.19-community, 3.20-community, 3.21-community, 3.22-community, 3.23-community, edge-community); fixed 32, open 0. | https://security.alpinelinux.org/vuln/CVE-2021-20271 |
debian
|
not yet assigned | CVE-2021-20271 not yet assigned priority: Debian including 1 source packages (rpm), 5 status rows across 5 suites (bookworm, bullseye, forky, sid, trixie): resolved 5. | https://security-tracker.debian.org/tracker/CVE-2021-20271 |
gentoo
|
normal | CVE-2021-20271: 1 GLSA(s) (202107-43), 1 atom(s) (app-arch/rpm); latest impact normal. | https://bugs.gentoo.org/buglist.cgi?quicksearch=CVE-2021-20271 |
redhat
|
medium | — | https://access.redhat.com/security/cve/CVE-2021-20271 |
suse
|
low | CVE-2021-20271 severity low: SUSE including 410 source package names (0.21.0.3.2.10:rpm-ndb-4.14.3-37.2, 0.7.1-rev1.0.0-build2.2.1:python3-rpm-4.14.3-37.2, …), 704 product×package rows across 201 product lines (Container bci/bci-init, Container bci/bci-minimal, … (201 product lines)): Fixed 410, Known Affected 231, Will Not Fix 63. | https://www.suse.com/security/cve/CVE-2021-20271/ |
ubuntu
|
low | CVE-2021-20271 low priority: Ubuntu including 1 source packages (rpm), 16 status rows across 16 suites (bionic, focal, groovy, hirsute, impish, jammy, kinetic, lunar, mantic, noble, oracular, plucky, questing, trusty, upstream, xenial): not-affected 8, released 4, ignored 3, needed 1. | https://ubuntu.com/security/CVE-2021-20271 |
| Vendor | Product | Version | Raw CPE |
|---|---|---|---|
| rpm | rpm | >= 4.15.0, < 4.15.1.3 | cpe:2.3:a:rpm:rpm:*:*:*:*:*:*:*:* |
| rpm | rpm | >= 4.16.0, < 4.16.1.3 | cpe:2.3:a:rpm:rpm:*:*:*:*:*:*:*:* |
| rpm | rpm | 4.15.0 | cpe:2.3:a:rpm:rpm:4.15.0:alpha:*:*:*:*:*:* |
| rpm | rpm | 4.15.0 | cpe:2.3:a:rpm:rpm:4.15.0:beta1:*:*:*:*:*:* |
| rpm | rpm | 4.15.0 | cpe:2.3:a:rpm:rpm:4.15.0:rc1:*:*:*:*:*:* |
| rpm | rpm | 4.16.0 | cpe:2.3:a:rpm:rpm:4.16.0:alpha:*:*:*:*:*:* |
| rpm | rpm | 4.16.0 | cpe:2.3:a:rpm:rpm:4.16.0:beta2:*:*:*:*:*:* |
| rpm | rpm | 4.16.0 | cpe:2.3:a:rpm:rpm:4.16.0:beta3:*:*:*:*:*:* |
| rpm | rpm | 4.16.0 | cpe:2.3:a:rpm:rpm:4.16.0:rc1:*:*:*:*:*:* |
| redhat | enterprise_linux | 8.0 | cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:*:*:*:* |
| fedoraproject | fedora | 32 | cpe:2.3:o:fedoraproject:fedora:32:*:*:*:*:*:*:* |
| fedoraproject | fedora | 33 | cpe:2.3:o:fedoraproject:fedora:33:*:*:*:*:*:*:* |
| fedoraproject | fedora | 34 | cpe:2.3:o:fedoraproject:fedora:34:*:*:*:*:*:*:* |
| starwindsoftware | starwind_virtual_san | v8 | cpe:2.3:a:starwindsoftware:starwind_virtual_san:v8:build14398:*:*:*:*:*:* |