CVE-2026-48863
EUVD-2026-4484216.07.2026, 01:16
A flaw was found in libsolv. A stack-based buffer overflow vulnerability exists in the PGP verification component due to incorrect length handling when copying EdDSA 's' MPI into a stack buffer. A remote attacker could craft a malicious Ed25519 PGP signature with mismatched MPI lengths. Processing this crafted signature could lead to a denial of service in automated package or repository processing workflows.Enginsight
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
| Vendor | Product | Version | Source |
|---|---|---|---|
| opensuse | libsolv | 0.6.4 ≤ 𝑥 < 0.7.38 | CNA |
Debian Releases
Ubuntu Releases
openSUSE / SLES Releases
openSUSE Product | |||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| libsolv-devel |
| ||||||||||||||||||
| libsolv-tools |
| ||||||||||||||||||
| libsolv-tools-base |
|
Amazon Linux Releases
Amazon Package | |||
|---|---|---|---|
| libsolv |
| ||
| libsolv-debuginfo |
| ||
| libsolv-debugsource |
| ||
| libsolv-demo |
| ||
| libsolv-demo-debuginfo |
| ||
| libsolv-devel |
| ||
| libsolv-tools |
| ||
| libsolv-tools-debuginfo |
| ||
| perl-solv |
| ||
| perl-solv-debuginfo |
| ||
| python3-solv |
| ||
| python3-solv-debuginfo |
| ||
| ruby-solv |
| ||
| ruby-solv-debuginfo |
|
Common Weakness Enumeration
References