top of page
perceptive_background_267k.jpg

A shellcode injection in the mercurial handler of the obs tar_scm source service before version 0.12.4 could be used by attackers able to provide a _service fil…

Published:

1 juli 2026 om 22:00:00

Alert date:

2 juli 2026 om 17:05:10

Source:

nvd.nist.gov

Click to open the original link from this advisory

Supply Chain & Dependencies, Zero-Day Vulnerabilities, Security Tools

CVE-2026-56004 describes a shellcode injection vulnerability in the Mercurial handler of the obs-service-tar_scm source service used in openSUSE Open Build Service (OBS). The flaw exists in versions before 0.12.4 and can be exploited by attackers who are able to supply a malicious _service file. Successful exploitation allows arbitrary code execution either as the source service process or as the local user who checks out the malicious service. The vulnerability is rooted in insufficient sanitization of inputs passed to the Mercurial handler. A patch has been proposed via a GitHub pull request to the openSUSE obs-service-tar_scm repository. The issue represents a supply chain risk as build environments processing attacker-controlled _service files could be compromised. Users are advised to upgrade to version 0.12.4 or later to mitigate the risk.

Technical details

Mitigation steps:

Affected products:

obs-service-tar_scm
openSUSE Open Build Service

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Deze website toont informatie afkomstig van externe bronnen; Perceptive aanvaardt geen verantwoordelijkheid voor de juistheid, volledigheid of actualiteit van deze informatie.

bottom of page