---
id: CVE-2026-9150
title: A flaw was found in libsolv
summary: >-
  A flaw was found in libsolv. This stack-based buffer overflow vulnerability
  occurs in libsolv's Debian metadata parser when processing specially crafted
  Debian repository metadata. An attacker could exploit this by providing
  malicious SH…
severity: medium
cvss: 6.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H'
cwe:
  - CWE-121
vendor: opensuse
product: libsolv
affected:
  - libsolv <= 0.7.36
  - hardened_images
  - openshift_container_platform = 4.0
  - satellite = 6.0
  - update_infrastructure = 4
  - enterprise_linux = 7.0
  - enterprise_linux = 8.0
  - enterprise_linux = 9.0
  - enterprise_linux = 10.0
published: '2026-05-20'
updated: '2026-07-31'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-9150'
references:
  - url: 'https://access.redhat.com/errata/RHSA-2026:21333'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2026:28236'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2026:30649'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2026:48818'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/security/cve/CVE-2026-9150'
    label: secalert@redhat.com
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2460379'
    label: secalert@redhat.com
  - url: 'https://github.com/openSUSE/libsolv/pull/616'
    label: secalert@redhat.com
tags:
  - nvd
epss: 0.00409
epssPercentile: 0.34876
ingestedAt: '2026-07-31T22:04:40.749Z'
---

## Overview

A flaw was found in libsolv. This stack-based buffer overflow vulnerability occurs in libsolv's Debian metadata parser when processing specially crafted Debian repository metadata. An attacker could exploit this by providing malicious SHA384 or SHA512 checksum tags, leading to memory corruption and a denial of service (DoS) in the affected system.

## Affected

- `libsolv <= 0.7.36`
- `hardened_images`
- `openshift_container_platform = 4.0`
- `satellite = 6.0`
- `update_infrastructure = 4`
- `enterprise_linux = 7.0`
- `enterprise_linux = 8.0`
- `enterprise_linux = 9.0`
- `enterprise_linux = 10.0`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
