CVE-2026-9150
published 2026-05-20CVE-2026-9150: A flaw was found in libsolv. This stack-based buffer overflow vulnerability occurs in libsolv's Debian metadata parser when processing specially crafted Debian…
PriorityP336medium6.5CVSS 3.1
AVNACLPRNUIRSUCNINAH
EPSS
0.40%
32.4th percentile
A flaw was found in libsolv. This stack-based buffer overflow vulnerability occurs in libsolv's Debian metadata parser when processing specially crafted Debian repository metadata. An attacker could exploit this by providing malicious SHA384 or SHA512 checksum tags, leading to memory corruption and a denial of service (DoS) in the affected system.
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| opensuse | libsolv | <= 0.7.36 | — |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux | — | — |
| redhat | openshift_container_platform | — | — |
| redhat | satellite | — | — |
| redhat | update_infrastructure | — | — |
| satellite-capsule_el8 | libsolv | — | — |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
vendor_redhat6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-p4w9-3pj8-mhq7: A flaw was found in libsolv
ghsa_unreviewed·2026-05-21
CVE-2026-9150 [MEDIUM] CWE-121 GHSA-p4w9-3pj8-mhq7: A flaw was found in libsolv
A flaw was found in libsolv. This stack-based buffer overflow vulnerability occurs in libsolv's Debian metadata parser when processing specially crafted Debian repository metadata. An attacker could exploit this by providing malicious SHA384 or SHA512 checksum tags, leading to memory corruption and a denial of service (DoS) in the affected system.
Red Hat
libsolv: Stack-based buffer overflow in libsolv's Debian metadata parser when handling SHA384/SHA512 checksums
vendor_redhat·2026-05-20·CVSS 6.5
CVE-2026-9150 [MEDIUM] CWE-121 libsolv: Stack-based buffer overflow in libsolv's Debian metadata parser when handling SHA384/SHA512 checksums
libsolv: Stack-based buffer overflow in libsolv's Debian metadata parser when handling SHA384/SHA512 checksums
A flaw was found in libsolv. This stack-based buffer overflow vulnerability occurs in libsolv's Debian metadata parser when processing specially crafted Debian repository metadata. An attacker could exploit this by providing malicious SHA384 or SHA512 checksum tags, leading to memory corruption and a denial of service (DoS) in the affected system.
Statement: This Moderate impact flaw in libsolv's Debian metadata parser can lead to a denial of service due to a stack-based buffer overflow. Exploitation requires a victim to process specially crafted, untrusted Debian repository metadata containing malicious SHA384 or SHA512 checksums. While memory corruption occurs, reliable system
No detection rules found.
No public exploits indexed.
2026-05-20
Published