VYPR

rpm package

almalinux/libsolv-tools-base

pkg:rpm/almalinux/libsolv-tools-base

Vulnerabilities (3)

  • CVE-2026-48864HigMay 26, 2026
    affected < 0.7.33-5.el10_2.alma.1fixed 0.7.33-5.el10_2.alma.1

    A flaw was found in libsolv. This heap buffer overflow occurs during the decompression of attacker-controlled compressed data within `.solv` files due to insufficient input validation. An attacker can provide a specially crafted `.solv` file, which, when processed by a vulnerable

  • CVE-2026-9149MedMay 21, 2026
    affected < 0.7.33-5.el10_2.alma.1fixed 0.7.33-5.el10_2.alma.1

    A flaw was found in libsolv. This heap buffer overflow vulnerability occurs when a victim processes a specially crafted `.solv` file containing negative size values in the `repo_add_solv` function. This leads to an undersized memory allocation and a subsequent out-of-bounds write

  • CVE-2026-9150MedMay 20, 2026
    affected < 0.7.33-5.el10_2.alma.1fixed 0.7.33-5.el10_2.alma.1

    A flaw was found in libsolv. This stack-based buffer overflow vulnerability occurs in libsolv's Debian metadata parser when processing specially crafted Debian repository metadata. An attacker could exploit this by providing malicious SHA384 or SHA512 checksum tags, leading to me