PT-2026-42272 · Libsolv · Libsolv

Found By

·

Published

2026-05-20

·

Updated

2026-05-29

·

CVE-2026-9150

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions libsolv (affected versions not specified)
Description A stack-based buffer overflow occurs in the Debian metadata parser of libsolv when processing specially crafted Debian repository metadata. An attacker can trigger this by providing malicious SHA384 or SHA512 checksum tags, resulting in memory corruption and a denial of service (DoS).
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

DoS

Stack Overflow

Weakness Enumeration

Related Identifiers

CVE-2026-9150
OPENSUSE-SU-2026:10895-1

Affected Products

Libsolv