Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-48863

Опубликовано: 26 мая 2026
Источник: redhat
CVSS3: 7.5
EPSS Низкий

Описание

A flaw was found in libsolv. A stack-based buffer overflow vulnerability exists in the PGP verification component due to incorrect length handling when copying EdDSA 's' MPI into a stack buffer. A remote attacker could craft a malicious Ed25519 PGP signature with mismatched MPI lengths. Processing this crafted signature could lead to a denial of service in automated package or repository processing workflows.

Отчет

This is an Important memory-safety flaw in libsolv's PGP verification component, which can be triggered by specially crafted Ed25519 signatures. The vulnerability allows for a stack-based buffer overflow, potentially leading to a denial of service in automated package or repository processing workflows when verifying attacker-controlled signed content or metadata. This vulnerability doesn't affect any support Red Hat products as the vulnerable function is only compiled when ENABLE_PUBKEY configuration is enabled during build time. Such configuration option is disabled when the libsolv package is built for Red Hat Enterprise Linux versions, thus the affected code is not present in the final distributed binary.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10libsolvNot affected
Red Hat Enterprise Linux 7libsolvNot affected
Red Hat Enterprise Linux 8libsolvNot affected
Red Hat Enterprise Linux 9libsolvNot affected
Red Hat Hardened ImageslibsolvNot affected
Red Hat OpenShift Container Platform 4rhcosNot affected
Red Hat Satellite 6satellite-capsule:el8/libsolvNot affected
Red Hat Update Infrastructure 4 for Cloud ProviderslibsolvNot affected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-121
https://bugzilla.redhat.com/show_bug.cgi?id=2460975libsolv: Stack-based buffer overflow in libsolv EdDSA PGP signature verification allows denial of service

EPSS

Процентиль: 38%
0.0047
Низкий

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
2 месяца назад

[Unknown description]

CVSS3: 7.5
nvd
20 дней назад

A flaw was found in libsolv. A stack-based buffer overflow vulnerability exists in the PGP verification component due to incorrect length handling when copying EdDSA 's' MPI into a stack buffer. A remote attacker could craft a malicious Ed25519 PGP signature with mismatched MPI lengths. Processing this crafted signature could lead to a denial of service in automated package or repository processing workflows.

CVSS3: 7.5
debian
20 дней назад

A flaw was found in libsolv. A stack-based buffer overflow vulnerabili ...

CVSS3: 7.5
github
20 дней назад

A flaw was found in libsolv. A stack-based buffer overflow vulnerability exists in the PGP verification component due to incorrect length handling when copying EdDSA 's' MPI into a stack buffer. A remote attacker could craft a malicious Ed25519 PGP signature with mismatched MPI lengths. Processing this crafted signature could lead to a denial of service in automated package or repository processing workflows.

suse-cvrf
около 2 месяцев назад

Security update for zypper, libzypp, libsolv

EPSS

Процентиль: 38%
0.0047
Низкий

7.5 High

CVSS3