VDB
CVE-2026-9150
CVE-2026-9150
PUBLISHED
CVSS 6.5 MEDIUM
A flaw was found in libsolv. This stack-based buffer overflow vulnerability occurs in libsolv's Debian metadata parser when processing specially crafted Debian repository metadata. An attacker could exploit this by providing malicious SHA384 or SHA512 checksum tags, leading to memory corruption and a denial of service (DoS) in the affected system.
EPSS 0.41% · 33.8th percentile
Risk Scores
CVSS 3.1
6.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
EPSS Score
0.41%
33.8th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Red Hat | Red Hat Enterprise Linux 7 | |
| Red Hat | Red Hat Enterprise Linux 8 | |
| Red Hat | Red Hat Enterprise Linux 9 | |
| Red Hat | Red Hat Hardened Images | |
| Red Hat | Red Hat Update Infrastructure 4 for Cloud Providers | |
| Red Hat | Red Hat OpenShift Container Platform 4 | |
| Red Hat | Red Hat Satellite 6 | |
| Red Hat | Red Hat Enterprise Linux 10 |
Timeline
- May 20, 2026 CVE Published
- May 21, 2026 EPSS Score
- May 21, 2026 Coalition ESS Score
- May 22, 2026 EPSS Score
- May 23, 2026 EPSS Score
- May 24, 2026 EPSS Score
- May 25, 2026 EPSS Score
- May 25, 2026 Security Advisory
- May 26, 2026 EPSS Score
- May 27, 2026 EPSS Score
- May 28, 2026 EPSS Score
- May 29, 2026 EPSS Score