Все бюллетени/c10f2/ALT-PU-2026-10233-3
ALT-PU-2026-10233-3

Обновление пакета libsolv в ветке c10f2

Версия0.7.39-alt1
Задание#423403
Опубликовано2026-07-01
Макс. серьёзностьMEDIUM
Серьёзность:

Закрытые проблемы (2)

CVE-2026-9149
MEDIUM6.5

A flaw was found in libsolv. This heap buffer overflow vulnerability occurs when a victim processes a specially crafted `.solv` file containing negative size values in the `repo_add_solv` function. This leads to an undersized memory allocation and a subsequent out-of-bounds write. An attacker could exploit this to cause a denial of service (DoS).

Опубликовано: 2026-05-20Изменено: 2026-06-26
CVSS 3.xСРЕДНЯЯ 6.5
CVSS:3.x/CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
CVE-2026-9150
MEDIUM6.5

A flaw was found in libsolv. This stack-based buffer overflow vulnerability occurs in libsolv's Debian metadata parser when processing specially crafted Debian repository metadata. An attacker could exploit this by providing malicious SHA384 or SHA512 checksum tags, leading to memory corruption and a denial of service (DoS) in the affected system.

Опубликовано: 2026-05-20Изменено: 2026-06-29
CVSS 3.xСРЕДНЯЯ 6.5
CVSS:3.x/CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H