Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2026-48864

Опубликовано: 26 мая 2026
Источник: debian
EPSS Низкий

Описание

A flaw was found in libsolv. This heap buffer overflow occurs during the decompression of attacker-controlled compressed data within `.solv` files due to insufficient input validation. An attacker can provide a specially crafted `.solv` file, which, when processed by a vulnerable application, can lead to out-of-bounds memory access. This could result in information disclosure, alteration of program execution, or a denial of service.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
libsolvunfixedpackage

Примечания

  • https://bugzilla.redhat.com/show_bug.cgi?id=2460425

  • Not considered a security risk per upstream, as issue is in solv file parser

EPSS

Процентиль: 11%
0.00205
Низкий

Связанные уязвимости

CVSS3: 7.8
ubuntu
2 месяца назад

A flaw was found in libsolv. This heap buffer overflow occurs during the decompression of attacker-controlled compressed data within `.solv` files due to insufficient input validation. An attacker can provide a specially crafted `.solv` file, which, when processed by a vulnerable application, can lead to out-of-bounds memory access. This could result in information disclosure, alteration of program execution, or a denial of service.

CVSS3: 7.8
redhat
2 месяца назад

A flaw was found in libsolv. This heap buffer overflow occurs during the decompression of attacker-controlled compressed data within `.solv` files due to insufficient input validation. An attacker can provide a specially crafted `.solv` file, which, when processed by a vulnerable application, can lead to out-of-bounds memory access. This could result in information disclosure, alteration of program execution, or a denial of service.

CVSS3: 7.8
nvd
2 месяца назад

A flaw was found in libsolv. This heap buffer overflow occurs during the decompression of attacker-controlled compressed data within `.solv` files due to insufficient input validation. An attacker can provide a specially crafted `.solv` file, which, when processed by a vulnerable application, can lead to out-of-bounds memory access. This could result in information disclosure, alteration of program execution, or a denial of service.

msrc
около 2 месяцев назад

Libsolv: heap buffer overflow in libsolv repopagestore via unchecked decompression of malicious .solv page data

rocky
16 дней назад

Moderate: libsolv security update

EPSS

Процентиль: 11%
0.00205
Низкий