Libsolv: heap buffer overflow in libsolv repopagestore via unchecked decompression of malicious .solv page data
Published May 26, 2026
7.8
HIGHCVSS 3.1
EPSS 0.26%
Description
A flaw was found in libsolv. This heap buffer overflow occurs during the decompression of attacker-controlled compressed data within `.solv` files due to insufficient input validation. An attacker can provide a specially crafted `.solv` file, which, when processed by a vulnerable application, can lead to out-of-bounds memory access. This could result in information disclosure, alteration of program execution, or a denial of service.
Affected products
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | |||
|---|---|---|---|---|---|---|
| Red Hat | Red Hat OpenShift Container Platform 4 | affected |
|
- 0.7.36
- n/a
- 4.0
- 6.0
- 4
- 7.0
- 8.0
- 9.0
- 10.0
No data.
Red Hat Discovery 2
discovery/discovery-server-rhel9:1784821670
Fixed · RHSA-2026:46836
Red Hat Discovery 2
discovery/discovery-ui-rhel9:1784821750
Fixed · RHSA-2026:46836
Red Hat Enterprise Linux 10
libsolv-0:0.7.33-5.el10_2
Fixed · RHSA-2026:28236
Red Hat Enterprise Linux 10.0 Extended Update Support
libsolv-0:0.7.29-8.el10_0.1
Fixed · RHSA-2026:48818
Red Hat Enterprise Linux 7 Extended Lifecycle Support
libsolv-0:0.6.34-4.el7_9.1
Fixed · RHSA-2026:49775
Red Hat Enterprise Linux 8
libsolv-0:0.7.20-7.el8_10
Fixed · RHSA-2026:36730
Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support
libsolv-0:0.7.16-3.el8_4.1
Fixed · RHSA-2026:48817
Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On
libsolv-0:0.7.16-3.el8_4.1
Fixed · RHSA-2026:48817
Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support
libsolv-0:0.7.20-1.el8_6.1
Fixed · RHSA-2026:48815
Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On
libsolv-0:0.7.20-1.el8_6.1
Fixed · RHSA-2026:48815
Red Hat Enterprise Linux 8.8 Telecommunications Update Service
libsolv-0:0.7.20-4.el8_8.1
Fixed · RHSA-2026:48816
Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions
libsolv-0:0.7.20-4.el8_8.1
Fixed · RHSA-2026:48816
Red Hat Enterprise Linux 9
libsolv-0:0.7.24-6.el9_8
Fixed · RHSA-2026:39315
Red Hat Enterprise Linux 9
libsolv-0:0.7.24-6.el9_8
Fixed · RHSA-2026:39315
Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions
libsolv-0:0.7.22-4.el9_2.1
Fixed · RHSA-2026:48814
Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions
libsolv-0:0.7.24-2.el9_4.1
Fixed · RHSA-2026:48813
Red Hat Enterprise Linux 9.6 Extended Update Support
libsolv-0:0.7.24-3.el9_6.1
Fixed · RHSA-2026:48811
Red Hat Hardened Images
libsolv-main-0.7.38-2.hum1
Fixed · RHSA-2026:21333
Red Hat Insights proxy 1.5
insights-proxy/insights-proxy-container-rhel9:1786433656
Fixed · RHSA-2026:53371
Red Hat OpenShift Container Platform 4.12
rhcos-412.86.202608241157-0
Fixed · RHSA-2026:59831
Red Hat OpenShift Container Platform 4.13
rhcos-413.92.202609080414-0
Fixed · RHSA-2026:65839
Red Hat OpenShift Container Platform 4.14
rhcos-414.92.202608172040-0
Fixed · RHSA-2026:56786
Red Hat OpenShift Container Platform 4.15
rhcos-415.92.202608180329-0
Fixed · RHSA-2026:56911
Red Hat OpenShift Container Platform 4.16
rhcos-416.94.202608150307-0
Fixed · RHSA-2026:56853
Red Hat OpenShift Container Platform 4.17
rhcos-417.94.202608250221-0
Fixed · RHSA-2026:60019
Red Hat OpenShift Container Platform 4.18
rhcos-418.94.202608142238-0
Fixed · RHSA-2026:57483
Red Hat OpenShift Container Platform 4.19
rhcos-4.19.9.6.202608182320-0
Fixed · RHSA-2026:57402
Red Hat Satellite 6.16 for RHEL 8
satellite-capsule:el8/libsolv-1:0.7.20-7.el8sat
Fixed · RHSA-2026:50223
Red Hat Satellite 6.16 for RHEL 8
satellite-capsule:el8/libsolv-1:0.7.20-7.el8sat
Fixed · RHSA-2026:50223
Red Hat Update Infrastructure 5
rhui5/cds-kubernetes-rhel9:1784794818
Fixed · RHSA-2026:44481
Red Hat Update Infrastructure 5
rhui5/cds-kubernetes-tp-rhel9:1787241211
Fixed · RHSA-2026:58981
Red Hat Update Infrastructure 5
rhui5/cds-rhel9:1784794778
Fixed · RHSA-2026:44481
Red Hat Update Infrastructure 5
rhui5/haproxy-rhel9:1784795112
Fixed · RHSA-2026:44481
Red Hat Update Infrastructure 5
rhui5/installer-rhel9:1784794289
Fixed · RHSA-2026:44481
Red Hat Update Infrastructure 5
rhui5/installer-tp-rhel9:1787135742
Fixed · RHSA-2026:58981
Red Hat Update Infrastructure 5
rhui5/rhua-rhel9:1784795076
Fixed · RHSA-2026:44481
Red Hat Update Infrastructure 5
rhui5/rhua-tp-rhel9:1787241260
Fixed · RHSA-2026:58981
Red Hat OpenShift Container Platform 4
openshift/ose-rhel-coreos-8
Affected
Red Hat Update Infrastructure 4 for Cloud Providers
libsolv
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Discovery 2 | discovery/discovery-server-rhel9:1784821670 | Fixed | RHSA-2026:46836 |
| Red Hat Discovery 2 | discovery/discovery-ui-rhel9:1784821750 | Fixed | RHSA-2026:46836 |
| Red Hat Enterprise Linux 10 | libsolv-0:0.7.33-5.el10_2 | Fixed | RHSA-2026:28236 |
| Red Hat Enterprise Linux 10.0 Extended Update Support | libsolv-0:0.7.29-8.el10_0.1 | Fixed | RHSA-2026:48818 |
| Red Hat Enterprise Linux 7 Extended Lifecycle Support | libsolv-0:0.6.34-4.el7_9.1 | Fixed | RHSA-2026:49775 |
| Red Hat Enterprise Linux 8 | libsolv-0:0.7.20-7.el8_10 | Fixed | RHSA-2026:36730 |
| Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support | libsolv-0:0.7.16-3.el8_4.1 | Fixed | RHSA-2026:48817 |
| Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On | libsolv-0:0.7.16-3.el8_4.1 | Fixed | RHSA-2026:48817 |
| Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support | libsolv-0:0.7.20-1.el8_6.1 | Fixed | RHSA-2026:48815 |
| Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On | libsolv-0:0.7.20-1.el8_6.1 | Fixed | RHSA-2026:48815 |
| Red Hat Enterprise Linux 8.8 Telecommunications Update Service | libsolv-0:0.7.20-4.el8_8.1 | Fixed | RHSA-2026:48816 |
| Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions | libsolv-0:0.7.20-4.el8_8.1 | Fixed | RHSA-2026:48816 |
| Red Hat Enterprise Linux 9 | libsolv-0:0.7.24-6.el9_8 | Fixed | RHSA-2026:39315 |
| Red Hat Enterprise Linux 9 | libsolv-0:0.7.24-6.el9_8 | Fixed | RHSA-2026:39315 |
| Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions | libsolv-0:0.7.22-4.el9_2.1 | Fixed | RHSA-2026:48814 |
| Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions | libsolv-0:0.7.24-2.el9_4.1 | Fixed | RHSA-2026:48813 |
| Red Hat Enterprise Linux 9.6 Extended Update Support | libsolv-0:0.7.24-3.el9_6.1 | Fixed | RHSA-2026:48811 |
| Red Hat Hardened Images | libsolv-main-0.7.38-2.hum1 | Fixed | RHSA-2026:21333 |
| Red Hat Insights proxy 1.5 | insights-proxy/insights-proxy-container-rhel9:1786433656 | Fixed | RHSA-2026:53371 |
| Red Hat OpenShift Container Platform 4.12 | rhcos-412.86.202608241157-0 | Fixed | RHSA-2026:59831 |
| Red Hat OpenShift Container Platform 4.13 | rhcos-413.92.202609080414-0 | Fixed | RHSA-2026:65839 |
| Red Hat OpenShift Container Platform 4.14 | rhcos-414.92.202608172040-0 | Fixed | RHSA-2026:56786 |
| Red Hat OpenShift Container Platform 4.15 | rhcos-415.92.202608180329-0 | Fixed | RHSA-2026:56911 |
| Red Hat OpenShift Container Platform 4.16 | rhcos-416.94.202608150307-0 | Fixed | RHSA-2026:56853 |
| Red Hat OpenShift Container Platform 4.17 | rhcos-417.94.202608250221-0 | Fixed | RHSA-2026:60019 |
| Red Hat OpenShift Container Platform 4.18 | rhcos-418.94.202608142238-0 | Fixed | RHSA-2026:57483 |
| Red Hat OpenShift Container Platform 4.19 | rhcos-4.19.9.6.202608182320-0 | Fixed | RHSA-2026:57402 |
| Red Hat Satellite 6.16 for RHEL 8 | satellite-capsule:el8/libsolv-1:0.7.20-7.el8sat | Fixed | RHSA-2026:50223 |
| Red Hat Satellite 6.16 for RHEL 8 | satellite-capsule:el8/libsolv-1:0.7.20-7.el8sat | Fixed | RHSA-2026:50223 |
| Red Hat Update Infrastructure 5 | rhui5/cds-kubernetes-rhel9:1784794818 | Fixed | RHSA-2026:44481 |
| Red Hat Update Infrastructure 5 | rhui5/cds-kubernetes-tp-rhel9:1787241211 | Fixed | RHSA-2026:58981 |
| Red Hat Update Infrastructure 5 | rhui5/cds-rhel9:1784794778 | Fixed | RHSA-2026:44481 |
| Red Hat Update Infrastructure 5 | rhui5/haproxy-rhel9:1784795112 | Fixed | RHSA-2026:44481 |
| Red Hat Update Infrastructure 5 | rhui5/installer-rhel9:1784794289 | Fixed | RHSA-2026:44481 |
| Red Hat Update Infrastructure 5 | rhui5/installer-tp-rhel9:1787135742 | Fixed | RHSA-2026:58981 |
| Red Hat Update Infrastructure 5 | rhui5/rhua-rhel9:1784795076 | Fixed | RHSA-2026:44481 |
| Red Hat Update Infrastructure 5 | rhui5/rhua-tp-rhel9:1787241260 | Fixed | RHSA-2026:58981 |
| Red Hat OpenShift Container Platform 4 | openshift/ose-rhel-coreos-8 | Affected | n/a |
| Red Hat Update Infrastructure 4 for Cloud Providers | libsolv | Not affected | n/a |
No package ranges for this CVE.
Remediation
Vendor solution
Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.
Red Hat statement
This heap buffer overflow in libsolv's page decompression logic can lead to out-of-bounds reads and writes when processing specially crafted `.solv` files. Exploitation requires a victim application to ingest malicious repository metadata, limiting the attack vector to scenarios involving user interaction or untrusted content sources. Given the user interaction needed, Red Hat Product Security has rated this vulnerability as having a impact of Moderate.
Red Hat mitigation
Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
No CVSS v3.0 score for this CVE.
No CVSS v2.0 score for this CVE.
This CVE is not in the KEV list.
CISA SSVC (Vulnrichment)
Stakeholder-Specific Vulnerability Categorization from CISA ADP.
Exploitation
NoneAutomatable
NoTechnical Impact
TotalDecision
n/aAssessed May 28, 2026 · SSVC 2.0.3
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
May–Oct 2026- EPSS v4
- EPSS v5
Percentile over time
- EPSS v4
- EPSS v5
Table of values (3 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 0.26% (0.00263) | 16.35th | v5 (v2026.06.15) |
| Jun 15, 2026 | 0.16% (0.00158) | 5.30th | v5 (v2026.06.15) |
| May 27, 2026 | 0.01% (0.00014) | 2.83th | v4 (v2025.03.14) |
References (48)
- https://access.redhat.com/errata/RHSA-2026:21333 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/errata/RHSA-2026:28236 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2026:36730 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2026:39315 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2026:44481 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2026:46836 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2026:48811 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2026:48813 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2026:48814 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2026:48815 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2026:48816 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2026:48817 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2026:48818 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2026:49775 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2026:50223 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2026:53371 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2026:56786 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2026:56853 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2026:56911 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2026:57402 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2026:57483 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2026:58981 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2026:59831 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2026:60019 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2026:65839 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2026:72394 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2026:72395 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2026:72399 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2026:72470 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2026:72475 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2026:72476 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2026:72502 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2026:73909 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2026:73959 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2026:73960 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2026:73961 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2026:73962 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2026:74458 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2026:74459 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2026:74460 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2026:74461 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2026:74462 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2026:74463 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2026:74674 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/security/cve/CVE-2026-48864 vdb-entryx_refsource_REDHATThird Party AdvisoryVendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2460425 issue-trackingx_refsource_REDHATExploitIssue TrackingThird Party Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-48864
- https://www.cve.org/CVERecord?id=CVE-2026-48864
Change history (0)
No recorded changes yet.