CVE-2026-9150
Low
No strong exploitation signal.
CVSS base
6.5
MEDIUM
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
EPSS — probability of exploitation (30 days)
0.4%
34.8th percentile
CISA KEV
Not listed
Weakness / dates
CWE-121
Published 2026-05-20 · modified 2026-09-01
CVSS breakdown
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
| Attack Vector | N | Network |
| Attack Complexity | L | Low |
| Privileges Required | N | None |
| User Interaction | R | Required |
| Scope | U | Unchanged |
| Confidentiality | N | None |
| Integrity | N | None |
| Availability | H | High |
Timeline
- 2026-05-20 — Published (NVD)
- 2026-09-01 — Last modified (NVD)
Description
A flaw was found in libsolv. This stack-based buffer overflow vulnerability occurs in libsolv's Debian metadata parser when processing specially crafted Debian repository metadata. An attacker could exploit this by providing malicious SHA384 or SHA512 checksum tags, leading to memory corruption and a denial of service (DoS) in the affected system.
Affected
References
- https://access.redhat.com/errata/RHSA-2026:21333
- https://access.redhat.com/errata/RHSA-2026:28236
- https://access.redhat.com/errata/RHSA-2026:30649
- https://access.redhat.com/errata/RHSA-2026:48818
- https://access.redhat.com/security/cve/CVE-2026-9150
- https://bugzilla.redhat.com/show_bug.cgi?id=2460379
- https://github.com/openSUSE/libsolv/pull/616