Moderate: libsolv security update. {"type": "TYPE_SECURITY", "shortCode": "RL", "name": "RLSA-2026:28236", "synopsis": "Moderate: libsolv security update", "severity": "SEVERITY_MODERATE", "topic": "An update is available for libsolv.\nThis update affects Rocky Linux 10.\nA Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE list", "description": "The libsolv packages provide a library for resolving package dependencies using a satisfiability algorithm.\n\nSecurity Fix(es):\n\n* libsolv: Stack-based buffer overflow in libsolv's Debian metadata parser when handling SHA384/SHA512 checksums (CVE-2026-9150)\n\n* libsolv: Heap buffer overflow in libsolv repo_add_solv via negative maxsize from crafted .solv file (CVE-2026-9149)\n\n* libsolv: Heap buffer overflow in libsolv repopagestore via unchecked decompression of malicious .solv page data (CVE-2026-48864)\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.", "solution": null, "affectedProducts": ["Rocky Linux 10"], "fixes": [{"ticket": "2460380", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2460380", "description": ""}, {"ticket": "2460379", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2460379", "description": ""}, {"ticket": "2460425", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2460425", "description": ""}], "cves": [{"name": "CVE-2026-48864", "sourceBy": "MITRE", "sourceLink": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-48864", "cvss3ScoringVector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", "cvss3BaseScore": "7.8", "cwe": "CWE-787"}, {"name": "CVE-2026-9149", "sourceBy": "MITRE", "sourceLink": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-9149", "cvss3ScoringVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H", "cvss3BaseScore": "6.5", "cwe": "CWE-122"}, {"name": "CVE-2026-9150", "sourceBy": "MITRE", "sourceLink": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-9150", "cvss3ScoringVector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H", "cvss3BaseScore": "6.5", "cwe": "CWE-121"}], "references": [], "publishedAt": "2026-06-24T12:05:09.232192Z", "rpms": {"Rocky Linux 10": {"nvras": ["libsolv-debuginfo-0:0.7.33-5.el10_2.aarch64.rpm", "libsolv-tools-debuginfo-0:0.7.33-5.el10_2.aarch64.rpm", "libsolv-tools-base-debuginfo-0:0.7.33-5.el10_2.s390x.rpm", "python3-solv-debuginfo-0:0.7.33-5.el10_2.ppc64le.rpm", "libsolv-debuginfo-0:0.7.33-5.el10_2.x86_64.rpm", "libsolv-debugsource-0:0.7.33-5.el10_2.ppc64le.rpm", "libsolv-tools-debuginfo-0:0.7.33-5.el10_2.s390x.rpm", "libsolv-devel-0:0.7.33-5.el10_2.x86_64.rpm", "libsolv-0:0.7.33-5.el10_2.src.rpm", "libsolv-tools-0:0.7.33-5.el10_2.s390x.rpm", "libsolv-debugsource-0:0.7.33-5.el10_2.s390x.rpm", "python3-solv-0:0.7.33-5.el10_2.s390x.rpm", "libsolv-debugsource-0:0.7.33-5.el10_2.x86_64.rpm", "libsolv-tools-base-0:0.7.33-5.el10_2.ppc64le.rpm", "python3-solv-debuginfo-0:0.7.33-5.el10_2.s390x.rpm", "libsolv-0:0.7.33-5.el10_2.ppc64le.rpm", "libsolv-debugsource-0:0.7.33-5.el10_2.aarch64.rpm", "libsolv-tools-base-0:0.7.33-5.el10_2.aarch64.rpm", "python3-solv-debuginfo-0:0.7.33-5.el10_2.aarch64.rpm", "libsolv-0:0.7.33-5.el10_2.aarch64.rpm", "libsolv-debuginfo-0:0.7.33-5.el10_2.ppc64le.rpm", "libsolv-tools-base-0:0.7.33-5.el10_2.s390x.rpm", "libsolv-0:0.7.33-5.el10_2.x86_64.rpm", "libsolv-devel-0:0.7.33-5.el10_2.aarch64.rpm", "python3-solv-0:0.7.33-5.el10_2.ppc64le.rpm", "libsolv-tools-base-debuginfo-0:0.7.33-5.el10_2.ppc64le.rpm", "libsolv-tools-base-debuginfo-0:0.7.33-5.el10_2.aarch64.rpm", "libsolv-tools-0:0.7.33-5.el10_2.x86_64.rpm", "python3-solv-0:0.7.33-5.el10_2.x86_64.rpm", "libsolv-0:0.7.33-5.el10_2.s390x.rpm", "python3-solv-debuginfo-0:0.7.33-5.el10_2.x86_64.rpm", "python3-solv-0:0.7.33-5.el10_2.aarch64.rpm","libsolv-devel-0:0.7.33-5.el10_2.ppc64le.rpm", "libsolv-tools-debuginfo-0:0.7.33-5.el10_2.x86_64.rpm", "libsolv-tools-base-0:0.7.33-5.el10_2.x86_64.rpm", "libsolv-devel-0:0.7.33-5.el10_2.s390x.rpm", "libsolv-debuginfo-0:0.7.33-5.el10_2.s390x.rpm", "libsolv-tools-0:0.7.33-5.el10_2.ppc64le.rpm", "libsolv-tools-debuginfo-0:0.7.33-5.el10_2.ppc64le.rpm", "libsolv-tools-base-debuginfo-0:0.7.33-5.el10_2.x86_64.rpm", "libsolv-tools-0:0.7.33-5.el10_2.aarch64.rpm"]}}, "rebootSuggested": false, "buildReferences": []}. Critical security advisory for Rocky Linux 10 updates libsolv with moderate buffer overflow risks impacting package handling.. libsolv security update, Rocky Linux 10, moderate security fix, dependency resolver, buffer overflow risk. . Severity: moderate. LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.