← voltar
CVE-2026-48863highCWE-121

Libsolv: stack-based buffer overflow in libsolv eddsa pgp signature verification allows denial of service

21Vexday Risk Score

Sem sinal de exploração. Nenhum artefato público de exploração conhecido até agora.

ssvc Trackcvss 7.5epss 0.5%
probabilidade de exploração
0.5%top 62% das CVEs
exploração observada
nãonenhuma fonte reporta
A flaw was found in libsolv. A stack-based buffer overflow vulnerability exists in the PGP verification component due to incorrect length handling when copying EdDSA 's' MPI into a stack buffer. A remote attacker could craft a malicious Ed25519 PGP signature with mismatched MPI lengths. Processing this crafted signature could lead to a denial of service in automated package or repository processing workflows.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H