CVE-2026-48863

Discovered by AISLEPUBLISHEDCWE-121

Description

A flaw was found in libsolv. A stack-based buffer overflow vulnerability exists in the PGP verification component due to incorrect length handling when copying EdDSA 's' MPI into a stack buffer. A remote attacker could craft a malicious Ed25519 PGP signature with mismatched MPI lengths. Processing this crafted signature could lead to a denial of service in automated package or repository processing workflows.

CVSS Base Scores

CVSS v3.1(Primary)
7.5

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Affected Products

VendorProductVersionStatus
OpenSUSElibsolv0.6.4affected
Red HatRed Hat Enterprise Linux 100.6.4affected
OpenSUSERed Hat Enterprise Linux 70.6.4affected
OpenSUSERed Hat Enterprise Linux 80.6.4affected
OpenSUSERed Hat Enterprise Linux 90.6.4affected
OpenSUSERed Hat Hardened Images0.6.4affected
OpenSUSERed Hat OpenShift Container Platform 40.6.4affected
OpenSUSERed Hat Satellite 60.6.4affected
OpenSUSERed Hat Update Infrastructure 4 for Cloud Providers0.6.4affected

Credits

  • This issue was discovered by AISLE Research and AISLE in partnership with Red Hat.

References