CVE-2021-44568
published 2022-02-21CVE-2021-44568: Two heap-overflow vulnerabilities exist in openSUSE/libsolv libsolv through 13 Dec 2020 in the decisionmap variable via the resolve_dependencies function at…
PriorityP428medium6.5CVSS 3.1
AVNACLPRNUIRSUCNINAH
EPSS
1.77%
75.5th percentile
Two heap-overflow vulnerabilities exist in openSUSE/libsolv libsolv through 13 Dec 2020 in the decisionmap variable via the resolve_dependencies function at src/solver.c (line 1940 & line 1995), which could cause a remote Denial of Service.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | libsolv | < libsolv 0.7.17-1 (bookworm) | libsolv 0.7.17-1 (bookworm) |
| opensuse | libsolv | < 0.7.17 | 0.7.17 |
| opensuse | libsolv | >= 0 < 0.7.17-1 | 0.7.17-1 |
| opensuse | libsolv | >= 0 < 0.7.17-1 | 0.7.17-1 |
| opensuse | libsolv | >= 0 < 0.7.17-1 | 0.7.17-1 |
| opensuse | libsolv | >= 0 < 0.7.17-1 | 0.7.17-1 |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:N/A:P
osv6.5MEDIUM
vendor_debian6.5LOW
vendor_redhat6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
libsolv: heap-overflows in resolve_dependencies function
vendor_redhat·2022-02-21·CVSS 6.5
CVE-2021-44568 [MEDIUM] CWE-125 libsolv: heap-overflows in resolve_dependencies function
libsolv: heap-overflows in resolve_dependencies function
Two heap-overflow vulnerabilities exist in openSUSE/libsolv libsolv through 13 Dec 2020 in the decisionmap variable via the resolve_dependencies function at src/solver.c (line 1940 & line 1995), which could cause a remote Denial of Service.
A buffer over-read flaw was found in the test case reader in libsolv that created multiple out-of-bounds read symptoms. Depending on how client applications use libsolv, this flaw leads to a denial of service of the application if an attacker can supply crafted input to the test case reader.
Statement: This flaw has been marked as Low impact because it is in the test case reader and is an out-of-bounds read.
This issue is related to already fixed issue (https://github.com/openSUSE/libsolv/commi
Debian
CVE-2021-44568: libsolv - Two heap-overflow vulnerabilities exist in openSUSE/libsolv libsolv through 13 D...
vendor_debian·2021·CVSS 6.5
CVE-2021-44568 [MEDIUM] CVE-2021-44568: libsolv - Two heap-overflow vulnerabilities exist in openSUSE/libsolv libsolv through 13 D...
Two heap-overflow vulnerabilities exist in openSUSE/libsolv libsolv through 13 Dec 2020 in the decisionmap variable via the resolve_dependencies function at src/solver.c (line 1940 & line 1995), which could cause a remote Denial of Service.
Scope: local
bookworm: resolved (fixed in 0.7.17-1)
bullseye: resolved (fixed in 0.7.17-1)
forky: resolved (fixed in 0.7.17-1)
sid: resolved (fixed in 0.7.17-1)
trixie: resolved (fixed in 0.7.17-1)
GHSA
GHSA-wmfm-g4qc-662g: Two heap-overflow vulnerabilities exist in openSUSE/libsolv libsolv through 13 Dec 2020 in the decisionmap variable via the resolve_dependencies funct
ghsa_unreviewed·2022-02-22
CVE-2021-44568 [MEDIUM] CWE-787 GHSA-wmfm-g4qc-662g: Two heap-overflow vulnerabilities exist in openSUSE/libsolv libsolv through 13 Dec 2020 in the decisionmap variable via the resolve_dependencies funct
Two heap-overflow vulnerabilities exist in openSUSE/libsolv libsolv through 13 Dec 2020 in the decisionmap variable via the resolve_dependencies function at src/solver.c (line 1940 & line 1995), which could cause a remote Denial of Service.
OSV
CVE-2021-44568: Two heap-overflow vulnerabilities exist in openSUSE/libsolv libsolv through 13 Dec 2020 in the decisionmap variable via the resolve_dependencies funct
osv·2022-02-21·CVSS 6.5
CVE-2021-44568 [MEDIUM] CVE-2021-44568: Two heap-overflow vulnerabilities exist in openSUSE/libsolv libsolv through 13 Dec 2020 in the decisionmap variable via the resolve_dependencies funct
Two heap-overflow vulnerabilities exist in openSUSE/libsolv libsolv through 13 Dec 2020 in the decisionmap variable via the resolve_dependencies function at src/solver.c (line 1940 & line 1995), which could cause a remote Denial of Service.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://github.com/openSUSE/libsolv/issues/425https://github.com/yangjiageng/PoC/blob/master/libsolv-PoCs/resolve_dependencies-1940https://github.com/yangjiageng/PoC/blob/master/libsolv-PoCs/resolve_dependencies-1995https://github.com/openSUSE/libsolv/issues/425https://github.com/yangjiageng/PoC/blob/master/libsolv-PoCs/resolve_dependencies-1940https://github.com/yangjiageng/PoC/blob/master/libsolv-PoCs/resolve_dependencies-1995
2022-02-21
Published