CVE-2026-48864

A flaw was found in libsolv. This heap buffer overflow occurs during the decompression of attacker-controlled compressed data within `.solv` files due to insufficient input validation. An attacker can provide a specially crafted `.solv` file, which, when processed by a vulnerable application, can le...

high 7.8 CVSS 3.1
Published: May 26, 2026
Modified: May 28, 2026
Vendor: Opensuse
Product: Libsolv
Versions: 0.7.36,4.0,6.0,4,7.0,8.0,9.0,10.0

Description

A flaw was found in libsolv. This heap buffer overflow occurs during the decompression of attacker-controlled compressed data within `.solv` files due to insufficient input validation. An attacker can provide a specially crafted `.solv` file, which, when processed by a vulnerable application, can lead to out-of-bounds memory access. This could result in information disclosure, alteration of program execution, or a denial of service.

References

Related CVEs