CVE-2026-48864
Undergoing Analysis
Undergoing Analysis - In Progress
Heap Buffer Overflow in libsolv via Malicious .solv Files
Publication date: 2026-05-26
Last updated on: 2026-05-28
Assigner: Red Hat, Inc.
Description
Description
A flaw was found in libsolv. This heap buffer overflow occurs during the decompression of attacker-controlled compressed data within `.solv` files due to insufficient input validation. An attacker can provide a specially crafted `.solv` file, which, when processed by a vulnerable application, can lead to out-of-bounds memory access. This could result in information disclosure, alteration of program execution, or a denial of service.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| redhat | enterprise_linux | 7.0 |
| redhat | satellite | 6.0 |
| redhat | enterprise_linux | 8.0 |
| redhat | openshift_container_platform | 4.0 |
| redhat | enterprise_linux | 9.0 |
| redhat | update_infrastructure | 4 |
| redhat | enterprise_linux | 10.0 |
| redhat | hardened_images | * |
| opensuse | libsolv | 0.7.36 |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-787 | The product writes data past the end, or before the beginning, of the intended buffer. |