A flaw was found in libsolv. This heap buffer overflow occurs during the decompression of attacker-controlled compressed data within `.solv` files due to insufficient input validation. An attacker can provide a specially crafted `.solv` file, which, when processed by a vulnerable application, can lead to out-of-bounds memory access. This could result in information disclosure, alteration of program execution, or a denial of service.
References
| Link | Resource |
|---|---|
| https://access.redhat.com/errata/RHSA-2026:21333 | Third Party Advisory |
| https://access.redhat.com/security/cve/CVE-2026-48864 | Third Party Advisory |
| https://bugzilla.redhat.com/show_bug.cgi?id=2460425 | Exploit Issue Tracking Third Party Advisory |
Configurations
Configuration 1 (hide)
|
History
28 May 2026, 19:22
| Type | Values Removed | Values Added |
|---|---|---|
| First Time |
Opensuse
Redhat update Infrastructure Redhat Redhat hardened Images Redhat satellite Opensuse libsolv Redhat enterprise Linux Redhat openshift Container Platform |
|
| References | () https://access.redhat.com/errata/RHSA-2026:21333 - Third Party Advisory | |
| References | () https://access.redhat.com/security/cve/CVE-2026-48864 - Third Party Advisory | |
| References | () https://bugzilla.redhat.com/show_bug.cgi?id=2460425 - Exploit, Issue Tracking, Third Party Advisory | |
| CPE | cpe:2.3:a:opensuse:libsolv:0.7.36:*:*:*:*:*:*:* cpe:2.3:o:redhat:enterprise_linux:10.0:*:*:*:*:*:*:* cpe:2.3:o:redhat:enterprise_linux:7.0:*:*:*:*:*:*:* cpe:2.3:a:redhat:hardened_images:-:*:*:*:*:*:*:* cpe:2.3:a:redhat:satellite:6.0:*:*:*:*:*:*:* cpe:2.3:o:redhat:enterprise_linux:9.0:*:*:*:*:*:*:* cpe:2.3:a:redhat:openshift_container_platform:4.0:*:*:*:*:*:*:* cpe:2.3:a:redhat:update_infrastructure:4:*:*:*:*:*:*:* cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:*:*:*:* |
28 May 2026, 14:16
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://bugzilla.redhat.com/show_bug.cgi?id=2460425 - |
28 May 2026, 03:16
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
26 May 2026, 18:16
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://bugzilla.redhat.com/show_bug.cgi?id=2460425 - |
26 May 2026, 17:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-05-26 17:16
Updated : 2026-05-28 19:22
NVD link : CVE-2026-48864
Mitre link : CVE-2026-48864
CVE.ORG link : CVE-2026-48864
JSON object : View
Products Affected
redhat
- update_infrastructure
- openshift_container_platform
- satellite
- enterprise_linux
- hardened_images
opensuse
- libsolv
CWE
CWE-787
Out-of-bounds Write
