Описание
ELSA-2026-28236: libsolv security update (MODERATE)
[0.7.33-5]
- Fix a buffer overflow when decompressing solv pages (CVE-2026-48864) (RHEL-178270)
[0.7.33-4]
- Cope with integer overflow in data size arithmetics in repo_add_solv() (CVE-2026-9149) (RHEL-178267)
[0.7.33-3]
- Fix a buffer overflow when copying SHA-384/512 checksum from a Debian repository (CVE-2026-9150) (RHEL-178263)
Обновленные пакеты
Oracle Linux 10
Oracle Linux aarch64
libsolv
0.7.33-5.el10_2
libsolv-devel
0.7.33-5.el10_2
libsolv-tools
0.7.33-5.el10_2
libsolv-tools-base
0.7.33-5.el10_2
python3-solv
0.7.33-5.el10_2
Oracle Linux x86_64
libsolv
0.7.33-5.el10_2
libsolv-devel
0.7.33-5.el10_2
libsolv-tools
0.7.33-5.el10_2
libsolv-tools-base
0.7.33-5.el10_2
python3-solv
0.7.33-5.el10_2
Связанные CVE
Связанные уязвимости
A flaw was found in libsolv. This heap buffer overflow occurs during the decompression of attacker-controlled compressed data within `.solv` files due to insufficient input validation. An attacker can provide a specially crafted `.solv` file, which, when processed by a vulnerable application, can lead to out-of-bounds memory access. This could result in information disclosure, alteration of program execution, or a denial of service.
A flaw was found in libsolv. This heap buffer overflow occurs during the decompression of attacker-controlled compressed data within `.solv` files due to insufficient input validation. An attacker can provide a specially crafted `.solv` file, which, when processed by a vulnerable application, can lead to out-of-bounds memory access. This could result in information disclosure, alteration of program execution, or a denial of service.
A flaw was found in libsolv. This heap buffer overflow occurs during the decompression of attacker-controlled compressed data within `.solv` files due to insufficient input validation. An attacker can provide a specially crafted `.solv` file, which, when processed by a vulnerable application, can lead to out-of-bounds memory access. This could result in information disclosure, alteration of program execution, or a denial of service.
Libsolv: heap buffer overflow in libsolv repopagestore via unchecked decompression of malicious .solv page data