Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

rocky логотип

RLSA-2026:28236

Опубликовано: 24 июн. 2026
Источник: rocky
Оценка: Moderate

Описание

Moderate: libsolv security update

The libsolv packages provide a library for resolving package dependencies using a satisfiability algorithm.

Security Fix(es):

  • libsolv: Stack-based buffer overflow in libsolv's Debian metadata parser when handling SHA384/SHA512 checksums (CVE-2026-9150)

  • libsolv: Heap buffer overflow in libsolv repo_add_solv via negative maxsize from crafted .solv file (CVE-2026-9149)

  • libsolv: Heap buffer overflow in libsolv repopagestore via unchecked decompression of malicious .solv page data (CVE-2026-48864)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Затронутые продукты

  • Rocky Linux 10

НаименованиеАрхитектураРелизRPM
libsolvaarch645.el10_2libsolv-0.7.33-5.el10_2.aarch64.rpm

Показывать по

Связанные уязвимости

oracle-oval
2 месяца назад

ELSA-2026-28236: libsolv security update (MODERATE)

CVSS3: 7.8
ubuntu
4 месяца назад

A flaw was found in libsolv. This heap buffer overflow occurs during the decompression of attacker-controlled compressed data within `.solv` files due to insufficient input validation. An attacker can provide a specially crafted `.solv` file, which, when processed by a vulnerable application, can lead to out-of-bounds memory access. This could result in information disclosure, alteration of program execution, or a denial of service.

CVSS3: 7.8
redhat
4 месяца назад

A flaw was found in libsolv. This heap buffer overflow occurs during the decompression of attacker-controlled compressed data within `.solv` files due to insufficient input validation. An attacker can provide a specially crafted `.solv` file, which, when processed by a vulnerable application, can lead to out-of-bounds memory access. This could result in information disclosure, alteration of program execution, or a denial of service.

CVSS3: 7.8
nvd
4 месяца назад

A flaw was found in libsolv. This heap buffer overflow occurs during the decompression of attacker-controlled compressed data within `.solv` files due to insufficient input validation. An attacker can provide a specially crafted `.solv` file, which, when processed by a vulnerable application, can lead to out-of-bounds memory access. This could result in information disclosure, alteration of program execution, or a denial of service.

msrc
4 месяца назад

Libsolv: heap buffer overflow in libsolv repopagestore via unchecked decompression of malicious .solv page data