Back

MEDIUM

libsolv: heap-overflows in resolve_dependencies function

Published Feb 21, 2022

Description

Two heap-overflow vulnerabilities exist in openSUSE/libsolv libsolv through 13 Dec 2020 in the decisionmap variable via the resolve_dependencies function at src/solver.c (line 1940 & line 1995), which could cause a remote Denial of Service.

Affected products

Remediation

Red Hat statement

This flaw has been marked as Low impact because it is in the test case reader and is an out-of-bounds read. This issue is related to already fixed issue (https://github.com/openSUSE/libsolv/commit/0077ef29eb46d2e1df2f230fc95a1d9748d49dec) that is part of libsolv-0.7.17. RHEL-8.6.z and above, and RHEL-9 ships versions of libsolv greater than 0.7.17. Hence, as the flaw is having LOW security impact, Red Hat Enterprise Linux - 8, 9 are set to not affected. However, RHEL-8 streams that ships libsolv versions prior to 0.7.17 are still affected. For additional information, refer to the Issue Severity Classification: https://access.redhat.com/security/updates/classification/ and Red Hat Enterprise Linux Life Cycle & Updates Policy: https://access.redhat.com/support/policy/updates/errata/.

References (8)

Change history (0)

No recorded changes yet.

Sources

CVE.org / MITRE

Status PUBLISHED
Assigner mitre
Published Feb 21, 2022
Updated Aug 4, 2024
Reserved Dec 6, 2021

CISA Vulnrichment

No data

NVD

Status Modified
Modified Jun 17, 2026

Red Hat

Severity Low
Public date Feb 21, 2022
Bugzilla 2057178

ENISA EUVD

Assigner mitre
Published Feb 21, 2022
Updated Aug 4, 2024

GitHub

No data