VDB

CVE-2026-9150

CVE-2026-9150 PUBLISHED CVSS 6.5 MEDIUM

A flaw was found in libsolv. This stack-based buffer overflow vulnerability occurs in libsolv's Debian metadata parser when processing specially crafted Debian repository metadata. An attacker could exploit this by providing malicious SHA384 or SHA512 checksum tags, leading to memory corruption and a denial of service (DoS) in the affected system.

EPSS 0.41% · 33.8th percentile

Risk Scores

CVSS 3.1
6.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
EPSS Score
0.41%
33.8th percentile

Affected Products

VendorProductVersions
Red HatRed Hat Enterprise Linux 7
Red HatRed Hat Enterprise Linux 8
Red HatRed Hat Enterprise Linux 9
Red HatRed Hat Hardened Images
Red HatRed Hat Update Infrastructure 4 for Cloud Providers
Red HatRed Hat OpenShift Container Platform 4
Red HatRed Hat Satellite 6
Red HatRed Hat Enterprise Linux 10

Timeline

  • May 20, 2026 CVE Published
  • May 21, 2026 EPSS Score
  • May 21, 2026 Coalition ESS Score
  • May 22, 2026 EPSS Score
  • May 23, 2026 EPSS Score
  • May 24, 2026 EPSS Score
  • May 25, 2026 EPSS Score
  • May 25, 2026 Security Advisory
  • May 26, 2026 EPSS Score
  • May 27, 2026 EPSS Score
  • May 28, 2026 EPSS Score
  • May 29, 2026 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›