CVE-2026-9150

A flaw was found in libsolv. This stack-based buffer overflow vulnerability occurs in libsolv's Debian metadata parser when processing specially crafted Debian repository metadata. An attacker could exploit this by providing malicious SHA384 or SHA512 checksum tags, leading to memory corruption and a denial of service (DoS) in the affected system.
References
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:opensuse:libsolv:*:*:*:*:*:*:*:*
cpe:2.3:a:redhat:hardened_images:-:*:*:*:*:*:*:*
cpe:2.3:a:redhat:openshift_container_platform:4.0:*:*:*:*:*:*:*
cpe:2.3:a:redhat:satellite:6.0:*:*:*:*:*:*:*
cpe:2.3:a:redhat:update_infrastructure:4:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:7.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:9.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:10.0:*:*:*:*:*:*:*

History

02 Jun 2026, 18:57

Type Values Removed Values Added
CPE cpe:2.3:a:opensuse:libsolv:*:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:10.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:7.0:*:*:*:*:*:*:*
cpe:2.3:a:redhat:hardened_images:-:*:*:*:*:*:*:*
cpe:2.3:a:redhat:satellite:6.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:9.0:*:*:*:*:*:*:*
cpe:2.3:a:redhat:openshift_container_platform:4.0:*:*:*:*:*:*:*
cpe:2.3:a:redhat:update_infrastructure:4:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:*:*:*:*
First Time Opensuse
Redhat update Infrastructure
Redhat
Redhat hardened Images
Redhat satellite
Opensuse libsolv
Redhat enterprise Linux
Redhat openshift Container Platform
References () https://access.redhat.com/security/cve/CVE-2026-9150 - () https://access.redhat.com/security/cve/CVE-2026-9150 - Third Party Advisory
References () https://bugzilla.redhat.com/show_bug.cgi?id=2460379 - () https://bugzilla.redhat.com/show_bug.cgi?id=2460379 - Issue Tracking, Third Party Advisory
References () https://github.com/openSUSE/libsolv/pull/616 - () https://github.com/openSUSE/libsolv/pull/616 - Issue Tracking, Patch

20 May 2026, 23:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-05-20 23:16

Updated : 2026-06-02 18:57


NVD link : CVE-2026-9150

Mitre link : CVE-2026-9150

CVE.ORG link : CVE-2026-9150


JSON object : View

Products Affected

redhat

  • update_infrastructure
  • openshift_container_platform
  • satellite
  • enterprise_linux
  • hardened_images

opensuse

  • libsolv
CWE
CWE-121

Stack-based Buffer Overflow