Описание
ELSA-2026-36730: libsolv security update (MODERATE)
[0.7.20-7]
- Fix a buffer overflow when decompressing solv pages (CVE-2026-48864) (RHEL-178970)
Обновленные пакеты
Oracle Linux 8
Oracle Linux aarch64
libsolv
0.7.20-7.el8_10
libsolv-devel
0.7.20-7.el8_10
libsolv-tools
0.7.20-7.el8_10
python3-solv
0.7.20-7.el8_10
Oracle Linux x86_64
libsolv
0.7.20-7.el8_10
libsolv-devel
0.7.20-7.el8_10
libsolv-tools
0.7.20-7.el8_10
python3-solv
0.7.20-7.el8_10
Связанные CVE
Связанные уязвимости
A flaw was found in libsolv. This heap buffer overflow occurs during the decompression of attacker-controlled compressed data within `.solv` files due to insufficient input validation. An attacker can provide a specially crafted `.solv` file, which, when processed by a vulnerable application, can lead to out-of-bounds memory access. This could result in information disclosure, alteration of program execution, or a denial of service.
A flaw was found in libsolv. This heap buffer overflow occurs during the decompression of attacker-controlled compressed data within `.solv` files due to insufficient input validation. An attacker can provide a specially crafted `.solv` file, which, when processed by a vulnerable application, can lead to out-of-bounds memory access. This could result in information disclosure, alteration of program execution, or a denial of service.
A flaw was found in libsolv. This heap buffer overflow occurs during the decompression of attacker-controlled compressed data within `.solv` files due to insufficient input validation. An attacker can provide a specially crafted `.solv` file, which, when processed by a vulnerable application, can lead to out-of-bounds memory access. This could result in information disclosure, alteration of program execution, or a denial of service.
Libsolv: heap buffer overflow in libsolv repopagestore via unchecked decompression of malicious .solv page data
A flaw was found in libsolv. This heap buffer overflow occurs during t ...