Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-48864— Libsolv: heap buffer overflow in libsolv repopagestore via unchecked decompression of malicious .solv page data

Quick assessment

Affected
Red Hat Red Hat Enterprise Linux 10
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

libsolv是openSUSE开源的一个用于检查软件包依赖的库。 libsolv存在安全漏洞,该漏洞源于解压攻击者控制的压缩数据时输入验证不足,导致堆缓冲区溢出,可能导致信息泄露、程序执行更改或拒绝服务。

CVSS 7.8 · High EPSS 0.26% · P16

Affected Version Matrix 52

VendorProduct Version RangeStatus
Red Hat Cert Manager support for Red Hat OpenShift release 1.20 1790223279< * unaffected
1790223719< * unaffected
1790272426< * unaffected
1790589998< * unaffected
1790589912< * unaffected
1790589914< * unaffected
1790589855< * unaffected
1790598593< * unaffected
Red Hat Red Hat Discovery 2 1784821670< * unaffected
1784821750< * unaffected
Red Hat Red Hat Enterprise Linux 10 0:0.7.33-5.el10_2< * unaffected
Red Hat Red Hat Enterprise Linux 10.0 Extended Update Support 0:0.7.29-8.el10_0.1< * unaffected
Red Hat Red Hat Enterprise Linux 7 Extended Lifecycle Support 0:0.6.34-4.el7_9.1< * unaffected
Red Hat Red Hat Enterprise Linux 8 0:0.7.20-7.el8_10< * unaffected
Red Hat Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support 0:0.7.16-3.el8_4.1< * unaffected
Red Hat Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On 0:0.7.16-3.el8_4.1< * unaffected
Red Hat Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support 0:0.7.20-1.el8_6.1< * unaffected
Red Hat Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On 0:0.7.20-1.el8_6.1< * unaffected
Red Hat Red Hat Enterprise Linux 8.8 Telecommunications Update Service 0:0.7.20-4.el8_8.1< * unaffected
Red Hat Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions 0:0.7.20-4.el8_8.1< * unaffected
Red Hat Red Hat Enterprise Linux 9 0:0.7.24-6.el9_8< * unaffected
0:0.7.24-6.el9_8< * unaffected
Red Hat Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions 0:0.7.22-4.el9_2.1< * unaffected
Red Hat Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions 0:0.7.24-2.el9_4.1< * unaffected
Red Hat Red Hat Enterprise Linux 9.6 Extended Update Support 0:0.7.24-3.el9_6.1< * unaffected
Red Hat Red Hat Hardened Images 0.7.38-2.hum1< * unaffected
Red Hat Red Hat Insights proxy 1.5 1786433656< * unaffected
Red Hat Red Hat OpenShift AI 3.0 1790276886< * unaffected
1790276884< * unaffected
1790277045< * unaffected
1790276889< * unaffected
1790276974< * unaffected
Red Hat Red Hat OpenShift Container Platform 4 any affected
Red Hat Red Hat OpenShift Container Platform 4.12 412.86.202608241157-0< * unaffected
Red Hat Red Hat OpenShift Container Platform 4.13 413.92.202609080414-0< * unaffected
Red Hat Red Hat OpenShift Container Platform 4.14 414.92.202608172040-0< * unaffected
Red Hat Red Hat OpenShift Container Platform 4.15 415.92.202608180329-0< * unaffected
Red Hat Red Hat OpenShift Container Platform 4.16 416.94.202608150307-0< * unaffected
Red Hat Red Hat OpenShift Container Platform 4.17 417.94.202608250221-0< * unaffected
Red Hat Red Hat OpenShift Container Platform 4.18 418.94.202608142238-0< * unaffected
Red Hat Red Hat OpenShift Container Platform 4.19 4.19.9.6.202608182320-0< * unaffected
Red Hat Red Hat Satellite 6.16 for RHEL 8 1:0.7.20-7.el8sat< * unaffected
1:0.7.20-7.el8sat< * unaffected
Red Hat Red Hat Update Infrastructure 4 for Cloud Providers any unaffected
Red Hat Red Hat Update Infrastructure 5 1784794818< * unaffected
1784794778< * unaffected
1784795112< * unaffected
1784794289< * unaffected
1784795076< * unaffected
1787241211< * unaffected
1787135742< * unaffected
1787241260< * unaffected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-48864

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Libsolv: heap buffer overflow in libsolv repopagestore via unchecked decompression of malicious .solv page data
Source: CVE Program / CVE List V5
Vulnerability Description
A flaw was found in libsolv. This heap buffer overflow occurs during the decompression of attacker-controlled compressed data within `.solv` files due to insufficient input validation. An attacker can provide a specially crafted `.solv` file, which, when processed by a vulnerable application, can lead to out-of-bounds memory access. This could result in information disclosure, alteration of program execution, or a denial of service.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
跨界内存写
Source: CVE Program / CVE List V5
Vulnerability Title
libsolv 安全漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
libsolv是openSUSE开源的一个用于检查软件包依赖的库。 libsolv存在安全漏洞,该漏洞源于解压攻击者控制的压缩数据时输入验证不足,导致堆缓冲区溢出,可能导致信息泄露、程序执行更改或拒绝服务。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

Vendor Product Affected Versions CPE Subscribe
Red Hat Red Hat Enterprise Linux 10 0:0.7.33-5.el10_2 ~ * cpe:/o:redhat:enterprise_linux:10.2
Red Hat Red Hat Enterprise Linux 10.0 Extended Update Support 0:0.7.29-8.el10_0.1 ~ * cpe:/o:redhat:enterprise_linux_eus:10.0
Red Hat Red Hat Enterprise Linux 7 Extended Lifecycle Support 0:0.6.34-4.el7_9.1 ~ * cpe:/o:redhat:rhel_els:7
Red Hat Red Hat Enterprise Linux 8 0:0.7.20-7.el8_10 ~ * cpe:/a:redhat:enterprise_linux:8::crb
Red Hat Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support 0:0.7.16-3.el8_4.1 ~ * cpe:/o:redhat:rhel_aus:8.4::baseos
Red Hat Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On 0:0.7.16-3.el8_4.1 ~ * cpe:/o:redhat:rhel_aus:8.4::baseos
Red Hat Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support 0:0.7.20-1.el8_6.1 ~ * cpe:/o:redhat:rhel_aus:8.6::baseos
Red Hat Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On 0:0.7.20-1.el8_6.1 ~ * cpe:/o:redhat:rhel_aus:8.6::baseos
Red Hat Red Hat Enterprise Linux 8.8 Telecommunications Update Service 0:0.7.20-4.el8_8.1 ~ * cpe:/o:redhat:rhel_e4s:8.8::baseos
Red Hat Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions 0:0.7.20-4.el8_8.1 ~ * cpe:/o:redhat:rhel_e4s:8.8::baseos
Red Hat Red Hat Enterprise Linux 9 0:0.7.24-6.el9_8 ~ * cpe:/a:redhat:enterprise_linux:9::appstream
Red Hat Red Hat Enterprise Linux 9 0:0.7.24-6.el9_8 ~ * cpe:/a:redhat:enterprise_linux:9::appstream
Red Hat Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions 0:0.7.22-4.el9_2.1 ~ * cpe:/a:redhat:rhel_e4s:9.2::appstream
Red Hat Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions 0:0.7.24-2.el9_4.1 ~ * cpe:/a:redhat:rhel_e4s:9.4::appstream
Red Hat Red Hat Enterprise Linux 9.6 Extended Update Support 0:0.7.24-3.el9_6.1 ~ * cpe:/a:redhat:rhel_eus:9.6::appstream
Red Hat Red Hat OpenShift Container Platform 4.12 412.86.202608241157-0 ~ * cpe:/a:redhat:openshift:4.12::el8
Red Hat Red Hat OpenShift Container Platform 4.13 413.92.202609080414-0 ~ * cpe:/a:redhat:openshift:4.13::el9
Red Hat Red Hat OpenShift Container Platform 4.14 414.92.202608172040-0 ~ * cpe:/a:redhat:openshift:4.14::el9
Red Hat Red Hat OpenShift Container Platform 4.15 415.92.202608180329-0 ~ * cpe:/a:redhat:openshift:4.15::el9
Red Hat Red Hat OpenShift Container Platform 4.16 416.94.202608150307-0 ~ * cpe:/a:redhat:openshift:4.16::el9
Red Hat Red Hat OpenShift Container Platform 4.17 417.94.202608250221-0 ~ * cpe:/a:redhat:openshift:4.17::el9
Red Hat Red Hat OpenShift Container Platform 4.18 418.94.202608142238-0 ~ * cpe:/a:redhat:openshift:4.18::el9
Red Hat Red Hat OpenShift Container Platform 4.19 4.19.9.6.202608182320-0 ~ * cpe:/a:redhat:openshift:4.19::el9
Red Hat Red Hat Satellite 6.16 for RHEL 8 1:0.7.20-7.el8sat ~ * cpe:/a:redhat:satellite:6.16::el8
Red Hat Red Hat Satellite 6.16 for RHEL 8 1:0.7.20-7.el8sat ~ * cpe:/a:redhat:satellite:6.16::el8
Red Hat Cert Manager support for Red Hat OpenShift release 1.20 1790223279 ~ * cpe:/a:redhat:cert_manager:1.20::el9
Red Hat Cert Manager support for Red Hat OpenShift release 1.20 1790223719 ~ * cpe:/a:redhat:cert_manager:1.20::el9
Red Hat Cert Manager support for Red Hat OpenShift release 1.20 1790272426 ~ * cpe:/a:redhat:cert_manager:1.20::el9
Red Hat Cert Manager support for Red Hat OpenShift release 1.20 1790589998 ~ * cpe:/a:redhat:cert_manager:1.20::el9
Red Hat Cert Manager support for Red Hat OpenShift release 1.20 1790589912 ~ * cpe:/a:redhat:cert_manager:1.20::el9

II. Public POCs for CVE-2026-48864

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-48864

请登录查看更多情报信息。

Vendor Advisories for CVE-2026-48864 (38)

Other References for CVE-2026-48864 (7)

IV. Related Vulnerabilities

V. Comments for CVE-2026-48864

No comments yet


Leave a comment