CVE-2026-9149 Details
Description
A flaw was found in libsolv. This heap buffer overflow vulnerability occurs when a victim processes a specially crafted `.solv` file containing negative size values in the `repo_add_solv` function. This leads to an undersized memory allocation and a subsequent out-of-bounds write. An attacker could exploit this to cause a denial of service (DoS).
A heap buffer overflow vulnerability has been identified in libsolv versions through 0.7.36. This vulnerability arises in the repo_add_solv function when processing specially crafted .solv files that contain negative size values. The negative values lead to insufficient memory allocation, allowing for out-of-bounds writes. An attacker could exploit this vulnerability, causing a denial-of-service condition by crashing the application or consuming excessive resources.
Users are advised to avoid processing untrusted .solv files with libsolv or any applications that use libsolv, such as Red Hat Satellite 6. Ensure that all .solv data comes from trusted sources. Red Hat has deferred fixes for this vulnerability in Red Hat Enterprise Linux 7, 8, 9, and in the OpenShift Container Platform 4. Red Hat Enterprise Linux 10 and Red Hat Hardened Images are affected, but no fix is currently available.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed May 21, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/openSUSE/libsolv/pull/617 | CISA-ADP | Issue TrackingPatch |
| https://access.redhat.com/errata/RHSA-2026:21333 | [email protected] | |
| https://access.redhat.com/errata/RHSA-2026:28236 | [email protected] | |
| https://access.redhat.com/errata/RHSA-2026:48818 | [email protected] | |
| https://access.redhat.com/security/cve/CVE-2026-9149 | [email protected] | Third Party Advisory |
| https://bugzilla.redhat.com/show_bug.cgi?id=2460380 | [email protected] | Issue TrackingThird Party Advisory |
| https://github.com/openSUSE/libsolv/pull/617 | [email protected] | Issue TrackingPatch |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-122 | Heap-based Buffer Overflow | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| opensuse libsolv | <= 0.7.36 |
CPE
Remediation
| |
| redhat hardened images | All versions |
CPE
Remediation
| |
| redhat openshift container platform | 4.0 |
CPE
Remediation
| |
| redhat satellite | 6.0 |
CPE
Remediation
| |
| redhat update infrastructure | 4 |
CPE
Remediation
| |
| redhat enterprise linux | 7.0 8.0 9.0 10.0 |
CPE
Remediation
| |
Change History
12 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 1, 2026 | CVE Modified | [email protected] |
| Aug 31, 2026 | CVE Modified | [email protected] |
| Aug 31, 2026 | CVE Modified | CISA-ADP |
| Jul 31, 2026 | CVE Modified | [email protected] |
| Jul 23, 2026 | CVE Translated | [email protected] |
| Jun 27, 2026 | CVE Modified | [email protected] |
| Jun 24, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jun 2, 2026 | Initial Analysis | [email protected] |
| May 21, 2026 | CVE Modified | CISA-ADP |
| May 21, 2026 | New CVE Received | [email protected] |