Описание
ELSA-2026-39315: libsolv security update (MODERATE)
[0.7.24-6]
- Fix a buffer overflow when decompressing solv pages (CVE-2026-48864) (RHEL-178982)
Обновленные пакеты
Oracle Linux 9
Oracle Linux aarch64
libsolv-devel
0.7.24-6.el9_8
libsolv-tools
0.7.24-6.el9_8
libsolv
0.7.24-6.el9_8
python3-solv
0.7.24-6.el9_8
Oracle Linux x86_64
python3-solv
0.7.24-6.el9_8
libsolv-devel
0.7.24-6.el9_8
libsolv-tools
0.7.24-6.el9_8
libsolv
0.7.24-6.el9_8
Связанные CVE
Связанные уязвимости
A flaw was found in libsolv. This heap buffer overflow occurs during the decompression of attacker-controlled compressed data within `.solv` files due to insufficient input validation. An attacker can provide a specially crafted `.solv` file, which, when processed by a vulnerable application, can lead to out-of-bounds memory access. This could result in information disclosure, alteration of program execution, or a denial of service.
A flaw was found in libsolv. This heap buffer overflow occurs during the decompression of attacker-controlled compressed data within `.solv` files due to insufficient input validation. An attacker can provide a specially crafted `.solv` file, which, when processed by a vulnerable application, can lead to out-of-bounds memory access. This could result in information disclosure, alteration of program execution, or a denial of service.
A flaw was found in libsolv. This heap buffer overflow occurs during the decompression of attacker-controlled compressed data within `.solv` files due to insufficient input validation. An attacker can provide a specially crafted `.solv` file, which, when processed by a vulnerable application, can lead to out-of-bounds memory access. This could result in information disclosure, alteration of program execution, or a denial of service.
Libsolv: heap buffer overflow in libsolv repopagestore via unchecked decompression of malicious .solv page data
A flaw was found in libsolv. This heap buffer overflow occurs during t ...