CVE-2021-3200
published 2021-05-18CVE-2021-3200: Buffer overflow vulnerability in libsolv 2020-12-13 via the Solver * testcase_read(Pool *pool, FILE *fp, const char *testcase, Queue *job, char **resultp, int…
PriorityP411low3.3CVSS 3.1
AVLACLPRNUIRSUCNINAL
EPSS
1.31%
67.3th percentile
Buffer overflow vulnerability in libsolv 2020-12-13 via the Solver * testcase_read(Pool *pool, FILE *fp, const char *testcase, Queue *job, char **resultp, int *resultflagsp function at src/testcase.c: line 2334, which could cause a denial of service
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | libsolv | < libsolv 0.7.17-1 (bookworm) | libsolv 0.7.17-1 (bookworm) |
| msrc | cm1_libsolv_0.7.19-1_on_cbl_mariner_1.0 | — | — |
| opensuse | libsolv | < 0.7.17 | 0.7.17 |
| opensuse | libsolv | >= 0 < 0.7.17-1 | 0.7.17-1 |
| opensuse | libsolv | >= 0 < 0.7.17-1 | 0.7.17-1 |
| opensuse | libsolv | >= 0 < 0.7.17-1 | 0.7.17-1 |
| opensuse | libsolv | >= 0 < 0.7.17-1 | 0.7.17-1 |
| oracle | communications_cloud_native_core_policy | — | — |
CVSS provenance
nvdv3.13.3LOWCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:N/A:P
osv3.3LOW
vendor_debian3.3LOW
vendor_msrc3.3LOW
vendor_oracle3.3LOW
vendor_redhat3.3LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Oracle
Oracle Oracle Communications Risk Matrix: Signaling (libsolv) — CVE-2021-3200
vendor_oracle·2022-04-15·CVSS 3.3
CVE-2021-3200 [LOW] Oracle Oracle Communications Risk Matrix: Signaling (libsolv) — CVE-2021-3200
Oracle Oracle Communications Risk Matrix: Signaling (libsolv) vulnerability
CVE: CVE-2021-3200
CVSS: 3.3
Protocol: None
Remote exploit: No
Affected versions: Local
Advisory: cpuapr2022 (APR 2022)
Red Hat
libsolv: Heap overflow
vendor_redhat·2022-02-21·CVSS 3.3
CVE-2021-44570 [LOW] CWE-787 libsolv: Heap overflow
libsolv: Heap overflow
[REJECTED CVE] Two heap-overflow vulnerabilities exists in openSUSE/libsolv through 13 Dec 2020 in the bugs in the solver_get_recommendations funtion function at src/solver.c: line 4286 & line 4305 FOR_PROVIDES.
Statement: This flaw was found to be a duplicate of CVE-2021-3200. Please see https://access.redhat.com/security/cve/CVE-2021-3200 for information about affected products and security errata.
Package: libsolv (Red Hat Enterprise Linux 7) - Not affected
Package: libsolv (Red Hat Enterprise Linux 8) - Not affected
Package: libsolv (Red Hat Enterprise Linux 9) - Not affected
Package: libsolv (Red Hat Satellite 6) - Not affected
Package: libsolv (Red Hat Update Infrastructure 3 for Cloud Providers) - Will not fix
Red Hat
libsolv: Heap overflow
vendor_redhat·2022-02-21·CVSS 3.3
CVE-2021-44569 [LOW] CWE-787 libsolv: Heap overflow
libsolv: Heap overflow
[REJECTED CVE] A heap-buffer openSUSE libsolv through 13 Dec 2020 exists in the solver_solve function at src/solver.c: line 3445.
Statement: This flaw was found to be a duplicate of CVE-2021-3200. Please see https://access.redhat.com/security/cve/CVE-2021-3200 for information about affected products and security errata.
Package: libsolv (Red Hat Enterprise Linux 7) - Not affected
Package: libsolv (Red Hat Enterprise Linux 8) - Not affected
Package: libsolv (Red Hat Enterprise Linux 9) - Not affected
Package: libsolv (Red Hat Satellite 6) - Not affected
Package: libsolv (Red Hat Update Infrastructure 3 for Cloud Providers) - Will not fix
Red Hat
libsolv: Heap overflow
vendor_redhat·2022-02-21·CVSS 3.3
CVE-2021-44571 [LOW] CWE-787 libsolv: Heap overflow
libsolv: Heap overflow
[REJECTED CVE] A heap overflow vulnerability exisfts in openSUSE libsolv through 13 Dec 2020 in the prefer_suggested function at src/policy.c: line 442.
Statement: This flaw was found to be a duplicate of CVE-2021-3200. Please see https://access.redhat.com/security/cve/CVE-2021-3200 for information about affected products and security errata.
Package: libsolv (Red Hat Enterprise Linux 7) - Not affected
Package: libsolv (Red Hat Enterprise Linux 8) - Not affected
Package: libsolv (Red Hat Enterprise Linux 9) - Not affected
Package: libsolv (Red Hat Satellite 6) - Not affected
Package: libsolv (Red Hat Update Infrastructure 3 for Cloud Providers) - Will not fix
Red Hat
libsolv: Heap overflow
vendor_redhat·2022-02-21·CVSS 3.3
CVE-2021-44574 [LOW] CWE-787 libsolv: Heap overflow
libsolv: Heap overflow
[REJECTED CVE] A heap-overflow vulnerability exists in openSUSE libsolv through 13 Dec 2020 in the resolve_jobrules function at src/solver.c at line 1599.
Statement: This flaw was found to be a duplicate of CVE-2021-3200. Please see https://access.redhat.com/security/cve/CVE-2021-3200 for information about affected products and security errata.
Package: libsolv (Red Hat Enterprise Linux 7) - Not affected
Package: libsolv (Red Hat Enterprise Linux 8) - Not affected
Package: libsolv (Red Hat Enterprise Linux 9) - Not affected
Package: libsolv (Red Hat Satellite 6) - Not affected
Package: libsolv (Red Hat Update Infrastructure 3 for Cloud Providers) - Will not fix
Red Hat
libsolv: Heap overflow
vendor_redhat·2022-02-21·CVSS 3.3
CVE-2021-44576 [LOW] CWE-787 libsolv: Heap overflow
libsolv: Heap overflow
[REJECTED CVE] Two memory vulnerabilities exists in openSUSE libsolv through 13 Dec 2020 in the resolve_weak function at src/solver.c: line 2222 and 2249.
Statement: This flaw was found to be a duplicate of CVE-2021-3200. Please see https://access.redhat.com/security/cve/CVE-2021-3200 for information about affected products and security errata.
Package: libsolv (Red Hat Enterprise Linux 7) - Not affected
Package: libsolv (Red Hat Enterprise Linux 8) - Not affected
Package: libsolv (Red Hat Enterprise Linux 9) - Not affected
Package: libsolv (Red Hat Satellite 6) - Not affected
Package: libsolv (Red Hat Update Infrastructure 3 for Cloud Providers) - Will not fix
Red Hat
libsolv: Heap overflow
vendor_redhat·2022-02-21·CVSS 3.3
CVE-2021-44575 [LOW] CWE-787 libsolv: Heap overflow
libsolv: Heap overflow
[REJECTED CVE] Two heap-overflow vulnerabilities exists in openSUSE libsolv through 13 Dec 2020 in the makeruledecisions function at src/solver.c: line 147 and 307.
Statement: This flaw was found to be a duplicate of CVE-2021-3200. Please see https://access.redhat.com/security/cve/CVE-2021-3200 for information about affected products and security errata.
Package: libsolv (Red Hat Enterprise Linux 7) - Not affected
Package: libsolv (Red Hat Enterprise Linux 8) - Not affected
Package: libsolv (Red Hat Enterprise Linux 9) - Not affected
Package: libsolv (Red Hat Satellite 6) - Not affected
Package: libsolv (Red Hat Update Infrastructure 3 for Cloud Providers) - Will not fix
Red Hat
libsolv: Heap overflow
vendor_redhat·2022-02-21·CVSS 3.3
CVE-2021-44577 [LOW] CWE-787 libsolv: Heap overflow
libsolv: Heap overflow
[REJECTED CVE] Two heap-overflow vulnerabilities exist in openSUSE libsolv through 13 Dec 2020 bugs in the propagate function at src/solver.c: line 490 and 524.
Statement: This flaw was found to be a duplicate of CVE-2021-3200. Please see https://access.redhat.com/security/cve/CVE-2021-3200 for information about affected products and security errata.
Package: libsolv (Red Hat Enterprise Linux 7) - Not affected
Package: libsolv (Red Hat Enterprise Linux 8) - Not affected
Package: libsolv (Red Hat Enterprise Linux 9) - Not affected
Package: libsolv (Red Hat Satellite 6) - Not affected
Package: libsolv (Red Hat Update Infrastructure 3 for Cloud Providers) - Will not fix
Red Hat
libsolv: Heap overflow
vendor_redhat·2022-02-21·CVSS 3.3
CVE-2021-44573 [LOW] CWE-787 libsolv: Heap overflow
libsolv: Heap overflow
[REJECTED CVE] Two heap overflow vulnerabilities exist in oenSUSE libsolv through 13 Dec 2020 in the resolve_installed function at src/solver.c: line 1728 & 1766.
Statement: This flaw was found to be a duplicate of CVE-2021-3200. Please see https://access.redhat.com/security/cve/CVE-2021-3200 for information about affected products and security errata.
Package: libsolv (Red Hat Enterprise Linux 7) - Not affected
Package: libsolv (Red Hat Enterprise Linux 8) - Not affected
Package: libsolv (Red Hat Enterprise Linux 9) - Not affected
Package: libsolv (Red Hat Satellite 6) - Not affected
Package: libsolv (Red Hat Update Infrastructure 3 for Cloud Providers) - Will not fix
Microsoft
Buffer overflow vulnerability in libsolv 2020-12-13 via the Solver * testcase_read(Pool *pool FILE *fp const char *testcase Queue *job char **resultp int *resultflagsp function at src/testcase.c: line
vendor_msrc·2021-05-11·CVSS 3.3
CVE-2021-3200 [LOW] CWE-120 Buffer overflow vulnerability in libsolv 2020-12-13 via the Solver * testcase_read(Pool *pool FILE *fp const char *testcase Queue *job char **resultp int *resultflagsp function at src/testcase.c: line
Buffer overflow vulnerability in libsolv 2020-12-13 via the Solver * testcase_read(Pool *pool FILE *fp const char *testcase Queue *job char **resultp int *resultflagsp function at src/testcase.c: line 2334 which could cause a denial of service
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog post for more information. If impact to additional
Debian
CVE-2021-3200: libsolv - Buffer overflow vulnerability in libsolv 2020-12-13 via the Solver * testcase_re...
vendor_debian·2021·CVSS 3.3
CVE-2021-3200 [LOW] CVE-2021-3200: libsolv - Buffer overflow vulnerability in libsolv 2020-12-13 via the Solver * testcase_re...
Buffer overflow vulnerability in libsolv 2020-12-13 via the Solver * testcase_read(Pool *pool, FILE *fp, const char *testcase, Queue *job, char **resultp, int *resultflagsp function at src/testcase.c: line 2334, which could cause a denial of service
Scope: local
bookworm: resolved (fixed in 0.7.17-1)
bullseye: resolved (fixed in 0.7.17-1)
forky: resolved (fixed in 0.7.17-1)
sid: resolved (fixed in 0.7.17-1)
trixie: resolved (fixed in 0.7.17-1)
Red Hat
libsolv: heap-based buffer overflow in testcase_read() in src/testcase.c
vendor_redhat·2020-12-13·CVSS 3.3
CVE-2021-3200 [LOW] CWE-20 libsolv: heap-based buffer overflow in testcase_read() in src/testcase.c
libsolv: heap-based buffer overflow in testcase_read() in src/testcase.c
Buffer overflow vulnerability in libsolv 2020-12-13 via the Solver * testcase_read(Pool *pool, FILE *fp, const char *testcase, Queue *job, char **resultp, int *resultflagsp function at src/testcase.c: line 2334, which could cause a denial of service
A flaw was found in libsolv. A buffer overflow vulnerability could cause a denial of service. The highest threat from this vulnerability is to system availability.
Statement: It is not clear how this flaw could cause denial of service in most practical situations in general, and it is not the case in Red Hat Enterprise Linux package management, therefore we have lowered the Impact to Low. This is due to the fact that it is a small out of bounds read triggered by the tes
GHSA
GHSA-cphx-qv3m-4vvc: Buffer overflow vulnerability in libsolv 2020-12-13 via the Solver * testcase_read(Pool *pool, FILE *fp, const char *testcase, Queue *job, char **resu
ghsa_unreviewed·2022-05-24
CVE-2021-3200 [MEDIUM] CWE-120 GHSA-cphx-qv3m-4vvc: Buffer overflow vulnerability in libsolv 2020-12-13 via the Solver * testcase_read(Pool *pool, FILE *fp, const char *testcase, Queue *job, char **resu
Buffer overflow vulnerability in libsolv 2020-12-13 via the Solver * testcase_read(Pool *pool, FILE *fp, const char *testcase, Queue *job, char **resultp, int *resultflagsp function at src/testcase.c: line 2334, which could cause a denial of service
OSV
CVE-2021-3200: Buffer overflow vulnerability in libsolv 2020-12-13 via the Solver * testcase_read(Pool *pool, FILE *fp, const char *testcase, Queue *job, char **resu
osv·2021-05-18·CVSS 3.3
CVE-2021-3200 [LOW] CVE-2021-3200: Buffer overflow vulnerability in libsolv 2020-12-13 via the Solver * testcase_read(Pool *pool, FILE *fp, const char *testcase, Queue *job, char **resu
Buffer overflow vulnerability in libsolv 2020-12-13 via the Solver * testcase_read(Pool *pool, FILE *fp, const char *testcase, Queue *job, char **resultp, int *resultflagsp function at src/testcase.c: line 2334, which could cause a denial of service
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://github.com/openSUSE/libsolv/issues/416https://github.com/yangjiageng/PoC/blob/master/libsolv-PoCs/PoC-testcase_read-2334https://www.oracle.com/security-alerts/cpuapr2022.htmlhttps://github.com/openSUSE/libsolv/issues/416https://github.com/yangjiageng/PoC/blob/master/libsolv-PoCs/PoC-testcase_read-2334https://www.oracle.com/security-alerts/cpuapr2022.html
2021-05-18
Published