Описание
A flaw was found in libsolv. A stack-based buffer overflow vulnerability exists in the PGP verification component due to incorrect length handling when copying EdDSA 's' MPI into a stack buffer. A remote attacker could craft a malicious Ed25519 PGP signature with mismatched MPI lengths. Processing this crafted signature could lead to a denial of service in automated package or repository processing workflows.
Отчет
This is an Important memory-safety flaw in libsolv's PGP verification component, which can be triggered by specially crafted Ed25519 signatures. The vulnerability allows for a stack-based buffer overflow, potentially leading to a denial of service in automated package or repository processing workflows when verifying attacker-controlled signed content or metadata. This vulnerability doesn't affect any support Red Hat products as the vulnerable function is only compiled when ENABLE_PUBKEY configuration is enabled during build time. Such configuration option is disabled when the libsolv package is built for Red Hat Enterprise Linux versions, thus the affected code is not present in the final distributed binary.
Меры по смягчению последствий
Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Enterprise Linux 10 | libsolv | Not affected | ||
| Red Hat Enterprise Linux 7 | libsolv | Not affected | ||
| Red Hat Enterprise Linux 8 | libsolv | Not affected | ||
| Red Hat Enterprise Linux 9 | libsolv | Not affected | ||
| Red Hat Hardened Images | libsolv | Not affected | ||
| Red Hat OpenShift Container Platform 4 | rhcos | Not affected | ||
| Red Hat Satellite 6 | satellite-capsule:el8/libsolv | Not affected | ||
| Red Hat Update Infrastructure 4 for Cloud Providers | libsolv | Not affected |
Показывать по
Дополнительная информация
Статус:
EPSS
7.5 High
CVSS3
Связанные уязвимости
A flaw was found in libsolv. A stack-based buffer overflow vulnerability exists in the PGP verification component due to incorrect length handling when copying EdDSA 's' MPI into a stack buffer. A remote attacker could craft a malicious Ed25519 PGP signature with mismatched MPI lengths. Processing this crafted signature could lead to a denial of service in automated package or repository processing workflows.
A flaw was found in libsolv. A stack-based buffer overflow vulnerabili ...
A flaw was found in libsolv. A stack-based buffer overflow vulnerability exists in the PGP verification component due to incorrect length handling when copying EdDSA 's' MPI into a stack buffer. A remote attacker could craft a malicious Ed25519 PGP signature with mismatched MPI lengths. Processing this crafted signature could lead to a denial of service in automated package or repository processing workflows.
EPSS
7.5 High
CVSS3