CVE-2026-9149
A flaw was found in libsolv. This heap buffer overflow vulnerability occurs when a victim processes a specially crafted `.solv` file containing negative size values in the `repo_add_solv` function. This leads to an undersized memory allocation and a subsequent out-of-bounds write. An attacker could exploit this to cause a denial of service (DoS).
Published:May 20, 2026
Last Modified:Jul 31, 2026
EPS:May 20, 2026
EPSS Score:0.00291
CVSS Score:6.5
Affected Products
Vendor
Product
Action
Vendor
Opensuse
Product
Libsolv
Opensuse
Libsolv
Vendor
Red Hat
Product
Red Hat Satellite 6
Red Hat
Red Hat Satellite 6
Vendor
Redhat
Product
Enterprise Linux
Redhat
Enterprise Linux
Vendor
Redhat
Product
Enterprise Linux Eus
Redhat
Enterprise Linux Eus
Vendor
Redhat
Product
Hardened Images
Redhat
Hardened Images
Vendor
Redhat
Product
Hummingbird
Redhat
Hummingbird
Vendor
Redhat
Product
Openshift
Redhat
Openshift
Vendor
Redhat
Product
Openshift Container Platform
Redhat
Openshift Container Platform
Vendor
Redhat
Product
Rhui
Redhat
Rhui
Vendor
Redhat
Product
Rsatellite
Redhat
Rsatellite
Vendor
Redhat
Product
Satellite
Redhat
Satellite
Vendor
Redhat
Product
Update Infrastructure
Redhat
Update Infrastructure
Exploits
No exploit reference
Common Weakness Enumeration
Common Attack Pattern Enumeration and Classification (CAPEC)
Related CVEs
References
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
