rpm package
almalinux/libsolv-devel
pkg:rpm/almalinux/libsolv-devel
Vulnerabilities (8)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2026-48864 | Hig | 7.8 | < 0.7.33-5.el10_2.alma.1 | 0.7.33-5.el10_2.alma.1 | May 26, 2026 | A flaw was found in libsolv. This heap buffer overflow occurs during the decompression of attacker-controlled compressed data within `.solv` files due to insufficient input validation. An attacker can provide a specially crafted `.solv` file, which, when processed by a vulnerable | |
| CVE-2026-9149 | Med | 6.5 | < 0.7.33-5.el10_2.alma.1 | 0.7.33-5.el10_2.alma.1 | May 21, 2026 | A flaw was found in libsolv. This heap buffer overflow vulnerability occurs when a victim processes a specially crafted `.solv` file containing negative size values in the `repo_add_solv` function. This leads to an undersized memory allocation and a subsequent out-of-bounds write | |
| CVE-2026-9150 | Med | 6.5 | < 0.7.33-5.el10_2.alma.1 | 0.7.33-5.el10_2.alma.1 | May 20, 2026 | A flaw was found in libsolv. This stack-based buffer overflow vulnerability occurs in libsolv's Debian metadata parser when processing specially crafted Debian repository metadata. An attacker could exploit this by providing malicious SHA384 or SHA512 checksum tags, leading to me | |
| CVE-2021-33938 | Hig | 7.5 | < 0.7.16-3.el8_4 | 0.7.16-3.el8_4 | Sep 2, 2021 | Buffer overflow vulnerability in function prune_to_recommended in src/policy.c in libsolv before 0.7.17 allows attackers to cause a Denial of Service. | |
| CVE-2021-33930 | Hig | 7.5 | < 0.7.16-3.el8_4 | 0.7.16-3.el8_4 | Sep 2, 2021 | Buffer overflow vulnerability in function pool_installable_whatprovides in src/repo.h in libsolv before 0.7.17 allows attackers to cause a Denial of Service. | |
| CVE-2021-33929 | Hig | 7.5 | < 0.7.16-3.el8_4 | 0.7.16-3.el8_4 | Sep 2, 2021 | Buffer overflow vulnerability in function pool_disabled_solvable in src/repo.h in libsolv before 0.7.17 allows attackers to cause a Denial of Service. | |
| CVE-2021-33928 | Hig | 7.5 | < 0.7.16-3.el8_4 | 0.7.16-3.el8_4 | Sep 2, 2021 | Buffer overflow vulnerability in function pool_installable in src/repo.h in libsolv before 0.7.17 allows attackers to cause a Denial of Service. | |
| CVE-2021-3200 | Low | 3.3 | < 0.7.19-1.el8 | 0.7.19-1.el8 | May 18, 2021 | Buffer overflow vulnerability in libsolv 2020-12-13 via the Solver * testcase_read(Pool *pool, FILE *fp, const char *testcase, Queue *job, char **resultp, int *resultflagsp function at src/testcase.c: line 2334, which could cause a denial of service |
- affected < 0.7.33-5.el10_2.alma.1fixed 0.7.33-5.el10_2.alma.1
A flaw was found in libsolv. This heap buffer overflow occurs during the decompression of attacker-controlled compressed data within `.solv` files due to insufficient input validation. An attacker can provide a specially crafted `.solv` file, which, when processed by a vulnerable
- affected < 0.7.33-5.el10_2.alma.1fixed 0.7.33-5.el10_2.alma.1
A flaw was found in libsolv. This heap buffer overflow vulnerability occurs when a victim processes a specially crafted `.solv` file containing negative size values in the `repo_add_solv` function. This leads to an undersized memory allocation and a subsequent out-of-bounds write
- affected < 0.7.33-5.el10_2.alma.1fixed 0.7.33-5.el10_2.alma.1
A flaw was found in libsolv. This stack-based buffer overflow vulnerability occurs in libsolv's Debian metadata parser when processing specially crafted Debian repository metadata. An attacker could exploit this by providing malicious SHA384 or SHA512 checksum tags, leading to me
- affected < 0.7.16-3.el8_4fixed 0.7.16-3.el8_4
Buffer overflow vulnerability in function prune_to_recommended in src/policy.c in libsolv before 0.7.17 allows attackers to cause a Denial of Service.
- affected < 0.7.16-3.el8_4fixed 0.7.16-3.el8_4
Buffer overflow vulnerability in function pool_installable_whatprovides in src/repo.h in libsolv before 0.7.17 allows attackers to cause a Denial of Service.
- affected < 0.7.16-3.el8_4fixed 0.7.16-3.el8_4
Buffer overflow vulnerability in function pool_disabled_solvable in src/repo.h in libsolv before 0.7.17 allows attackers to cause a Denial of Service.
- affected < 0.7.16-3.el8_4fixed 0.7.16-3.el8_4
Buffer overflow vulnerability in function pool_installable in src/repo.h in libsolv before 0.7.17 allows attackers to cause a Denial of Service.
- affected < 0.7.19-1.el8fixed 0.7.19-1.el8
Buffer overflow vulnerability in libsolv 2020-12-13 via the Solver * testcase_read(Pool *pool, FILE *fp, const char *testcase, Queue *job, char **resultp, int *resultflagsp function at src/testcase.c: line 2334, which could cause a denial of service