---
id: CVE-2026-48863
title: A flaw was found in libsolv
summary: >-
  A flaw was found in libsolv. A stack-based buffer overflow vulnerability
  exists in the PGP verification component due to incorrect length handling when
  copying EdDSA 's' MPI into a stack buffer. A remote attacker could craft a
  malicious …
severity: high
cvss: 7.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'
cwe:
  - CWE-121
  - CWE-121
published: '2026-07-16'
updated: '2026-07-18'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-48863'
references:
  - url: 'https://access.redhat.com/security/cve/CVE-2026-48863'
    label: secalert@redhat.com
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2460975'
    label: secalert@redhat.com
  - url: >-
      https://github.com/openSUSE/libsolv/commit/44f8c085045b1f771641091bbb2b810d12cff9e8#diff-309f245ec9b669ec78b8159c39e6f50130b4d4a0448f742685f7833d04bc4caaR592
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/security/cve/CVE-2026-48863'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2460975'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: >-
      https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-48863.json
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
tags:
  - nvd
epss: 0.0047
epssPercentile: 0.39834
ingestedAt: '2026-07-18T18:24:14.415Z'
---

## Overview

A flaw was found in libsolv. A stack-based buffer overflow vulnerability exists in the PGP verification component due to incorrect length handling when copying EdDSA 's' MPI into a stack buffer. A remote attacker could craft a malicious Ed25519 PGP signature with mismatched MPI lengths. Processing this crafted signature could lead to a denial of service in automated package or repository processing workflows.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
