CVE-2026-48863
published 2026-07-16CVE-2026-48863: A flaw was found in libsolv. A stack-based buffer overflow vulnerability exists in the PGP verification component due to incorrect length handling when copying…
PriorityP346high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
0.47%
38.0th percentile
A flaw was found in libsolv. A stack-based buffer overflow vulnerability exists in the PGP verification component due to incorrect length handling when copying EdDSA 's' MPI into a stack buffer. A remote attacker could craft a malicious Ed25519 PGP signature with mismatched MPI lengths. Processing this crafted signature could lead to a denial of service in automated package or repository processing workflows.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| opensuse | libsolv | >= 0.6.4 < 0.7.38 | 0.7.38 |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
A flaw was found in libsolv.
ghsa_unreviewed·2026-07-16
CVE-2026-48863 [HIGH] CWE-121 A flaw was found in libsolv.
A flaw was found in libsolv. A stack-based buffer overflow vulnerability exists in the PGP verification component due to incorrect length handling when copying EdDSA 's' MPI into a stack buffer. A remote attacker could craft a malicious Ed25519 PGP signature with mismatched MPI lengths. Processing this crafted signature could lead to a denial of service in automated package or repository processing workflows.
VulDB
libsolv EdDSA PGP Signature Verification stack-based overflow
vuldb·2026-05-28
CVE-2026-48863 [LOW] libsolv EdDSA PGP Signature Verification stack-based overflow
A vulnerability identified as critical has been detected in libsolv. This affects an unknown part of the component EdDSA PGP Signature Verification. This manipulation causes stack-based buffer overflow.
This vulnerability is tracked as CVE-2026-48863. The attack is only possible within the local network. No exploit exists.
You should upgrade the affected component.
Red Hat
libsolv: Stack-based buffer overflow in libsolv EdDSA PGP signature verification allows denial of service
vendor_redhat·2026-05-26·CVSS 7.5
CVE-2026-48863 [HIGH] CWE-121 libsolv: Stack-based buffer overflow in libsolv EdDSA PGP signature verification allows denial of service
libsolv: Stack-based buffer overflow in libsolv EdDSA PGP signature verification allows denial of service
A flaw was found in libsolv. A stack-based buffer overflow vulnerability exists in the PGP verification component due to incorrect length handling when copying EdDSA 's' MPI into a stack buffer. A remote attacker could craft a malicious Ed25519 PGP signature with mismatched MPI lengths. Processing this crafted signature could lead to a denial of service in automated package or repository processing workflows.
Statement: This is an Important memory-safety flaw in libsolv's PGP verification component, which can be triggered by specially crafted Ed25519 signatures. The vulnerability allows for a stack-based buffer overflow, potentially leading to a denial of service in automated package
No detection rules found.
No public exploits indexed.
https://access.redhat.com/security/cve/CVE-2026-48863https://bugzilla.redhat.com/show_bug.cgi?id=2460975https://github.com/openSUSE/libsolv/commit/44f8c085045b1f771641091bbb2b810d12cff9e8#diff-309f245ec9b669ec78b8159c39e6f50130b4d4a0448f742685f7833d04bc4caaR592https://access.redhat.com/security/cve/CVE-2026-48863https://bugzilla.redhat.com/show_bug.cgi?id=2460975https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-48863.json
2026-07-16
Published