GHSA-p3x5-f8vr-q28xHighCVSS 7.5
A flaw was found in libsolv. A stack-based buffer overflow vulnerability exists in the PGP...
🔗 CVE IDs covered (1)
📋 Description
A flaw was found in libsolv. A stack-based buffer overflow vulnerability exists in the PGP verification component due to incorrect length handling when copying EdDSA 's' MPI into a stack buffer. A remote attacker could craft a malicious Ed25519 PGP signature with mismatched MPI lengths. Processing this crafted signature could lead to a denial of service in automated package or repository processing workflows.
🔗 References (5)
- https://nvd.nist.gov/vuln/detail/CVE-2026-48863
- https://github.com/openSUSE/libsolv/commit/44f8c085045b1f771641091bbb2b810d12cff9e8#diff-309f245ec9b669ec78b8159c39e6f50130b4d4a0448f742685f7833d04bc4caaR592
- https://access.redhat.com/security/cve/CVE-2026-48863
- https://bugzilla.redhat.com/show_bug.cgi?id=2460975
- https://github.com/advisories/GHSA-p3x5-f8vr-q28x