Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

oracle-oval логотип

ELSA-2026-39315

Опубликовано: 14 июл. 2026
Источник: oracle-oval
Платформа: Oracle Linux 9

Описание

ELSA-2026-39315: libsolv security update (MODERATE)

[0.7.24-6]

  • Fix a buffer overflow when decompressing solv pages (CVE-2026-48864) (RHEL-178982)

Обновленные пакеты

Oracle Linux 9

Oracle Linux aarch64

libsolv-devel

0.7.24-6.el9_8

libsolv-tools

0.7.24-6.el9_8

libsolv

0.7.24-6.el9_8

python3-solv

0.7.24-6.el9_8

Oracle Linux x86_64

python3-solv

0.7.24-6.el9_8

libsolv-devel

0.7.24-6.el9_8

libsolv-tools

0.7.24-6.el9_8

libsolv

0.7.24-6.el9_8

Связанные CVE

Связанные уязвимости

CVSS3: 7.8
ubuntu
2 месяца назад

A flaw was found in libsolv. This heap buffer overflow occurs during the decompression of attacker-controlled compressed data within `.solv` files due to insufficient input validation. An attacker can provide a specially crafted `.solv` file, which, when processed by a vulnerable application, can lead to out-of-bounds memory access. This could result in information disclosure, alteration of program execution, or a denial of service.

CVSS3: 7.8
redhat
2 месяца назад

A flaw was found in libsolv. This heap buffer overflow occurs during the decompression of attacker-controlled compressed data within `.solv` files due to insufficient input validation. An attacker can provide a specially crafted `.solv` file, which, when processed by a vulnerable application, can lead to out-of-bounds memory access. This could result in information disclosure, alteration of program execution, or a denial of service.

CVSS3: 7.8
nvd
2 месяца назад

A flaw was found in libsolv. This heap buffer overflow occurs during the decompression of attacker-controlled compressed data within `.solv` files due to insufficient input validation. An attacker can provide a specially crafted `.solv` file, which, when processed by a vulnerable application, can lead to out-of-bounds memory access. This could result in information disclosure, alteration of program execution, or a denial of service.

msrc
около 2 месяцев назад

Libsolv: heap buffer overflow in libsolv repopagestore via unchecked decompression of malicious .solv page data

CVSS3: 7.8
debian
2 месяца назад

A flaw was found in libsolv. This heap buffer overflow occurs during t ...