CVE-2026-9150 Details
Description
A flaw was found in libsolv. This stack-based buffer overflow vulnerability occurs in libsolv's Debian metadata parser when processing specially crafted Debian repository metadata. An attacker could exploit this by providing malicious SHA384 or SHA512 checksum tags, leading to memory corruption and a denial of service (DoS) in the affected system.
A stack-based buffer overflow vulnerability has been identified in libsolv's Debian metadata parser. This flaw occurs when the parser processes specially crafted Debian repository metadata containing malicious SHA384 or SHA512 checksum tags. The vulnerability leads to memory corruption and a denial-of-service condition on the affected system.
To mitigate this vulnerability, it is recommended to only process trusted and cryptographically signed Debian repository metadata. Avoid handling untrusted 'Packages' files until the vulnerability has been addressed.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed May 21, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-121 | Stack-based Buffer Overflow | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| opensuse libsolv | <= 0.7.36 |
CPE
Remediation
| |
| redhat hardened images | All versions |
CPE
Remediation
| |
| redhat openshift container platform | 4.0 |
CPE
Remediation
| |
| redhat satellite | 6.0 |
CPE
Remediation
| |
| redhat update infrastructure | 4 |
CPE
Remediation
| |
| redhat enterprise linux | 7.0 8.0 9.0 10.0 |
CPE
Remediation
| |
Change History
11 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 1, 2026 | CVE Modified | [email protected] |
| Aug 31, 2026 | CVE Modified | [email protected] |
| Jul 31, 2026 | CVE Modified | [email protected] |
| Jul 23, 2026 | CVE Translated | [email protected] |
| Jun 29, 2026 | CVE Modified | [email protected] |
| Jun 27, 2026 | CVE Modified | [email protected] |
| Jun 24, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 2, 2026 | Initial Analysis | [email protected] |
| May 20, 2026 | New CVE Received | [email protected] |