Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-48864

Опубликовано: 26 мая 2026
Источник: redhat
CVSS3: 7.8
EPSS Низкий

Описание

A flaw was found in libsolv. This heap buffer overflow occurs during the decompression of attacker-controlled compressed data within .solv files due to insufficient input validation. An attacker can provide a specially crafted .solv file, which, when processed by a vulnerable application, can lead to out-of-bounds memory access. This could result in information disclosure, alteration of program execution, or a denial of service.

Отчет

This heap buffer overflow in libsolv's page decompression logic can lead to out-of-bounds reads and writes when processing specially crafted .solv files. Exploitation requires a victim application to ingest malicious repository metadata, limiting the attack vector to scenarios involving user interaction or untrusted content sources. Given the user interaction needed, Red Hat Product Security has rated this vulnerability as having a impact of Moderate.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 7libsolvAffected
Red Hat OpenShift Container Platform 4rhcosAffected
Red Hat Satellite 6satellite-capsule:el8/libsolvAffected
Red Hat Update Infrastructure 4 for Cloud ProviderslibsolvNot affected
Red Hat Enterprise Linux 10libsolvFixedRHSA-2026:2823623.06.2026
Red Hat Enterprise Linux 8libsolvFixedRHSA-2026:3673008.07.2026
Red Hat Enterprise Linux 9libsolvFixedRHSA-2026:3931514.07.2026
Red Hat Enterprise Linux 9libsolvFixedRHSA-2026:3931514.07.2026
Red Hat Discovery 2discovery/discovery-server-rhel9FixedRHSA-2026:4683627.07.2026
Red Hat Discovery 2discovery/discovery-ui-rhel9FixedRHSA-2026:4683627.07.2026

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-787
https://bugzilla.redhat.com/show_bug.cgi?id=2460425libsolv: Heap buffer overflow in libsolv repopagestore via unchecked decompression of malicious .solv page data

EPSS

Процентиль: 11%
0.00205
Низкий

7.8 High

CVSS3

Связанные уязвимости

CVSS3: 7.8
ubuntu
2 месяца назад

A flaw was found in libsolv. This heap buffer overflow occurs during the decompression of attacker-controlled compressed data within `.solv` files due to insufficient input validation. An attacker can provide a specially crafted `.solv` file, which, when processed by a vulnerable application, can lead to out-of-bounds memory access. This could result in information disclosure, alteration of program execution, or a denial of service.

CVSS3: 7.8
nvd
2 месяца назад

A flaw was found in libsolv. This heap buffer overflow occurs during the decompression of attacker-controlled compressed data within `.solv` files due to insufficient input validation. An attacker can provide a specially crafted `.solv` file, which, when processed by a vulnerable application, can lead to out-of-bounds memory access. This could result in information disclosure, alteration of program execution, or a denial of service.

msrc
около 2 месяцев назад

Libsolv: heap buffer overflow in libsolv repopagestore via unchecked decompression of malicious .solv page data

CVSS3: 7.8
debian
2 месяца назад

A flaw was found in libsolv. This heap buffer overflow occurs during t ...

rocky
16 дней назад

Moderate: libsolv security update

EPSS

Процентиль: 11%
0.00205
Низкий

7.8 High

CVSS3