A flaw was found in libsolv. This heap buffer overflow vulnerability occurs when a victim processes a specially crafted .solv file containing negative size values in the repo_add_solv function. This leads to an undersized memory allocation and a subsequent out-of-bounds write. An attacker could exploit this to cause a denial of service (DoS).
A heap overflow condition is a buffer overflow, where the buffer that can be overwritten is allocated in the heap portion of memory, generally meaning that the buffer was allocated using a routine such as malloc().
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Libsolv | Opensuse | * | 0.7.36 (including) |
| Hardened_images | Redhat | - (including) | - (including) |
| Openshift_container_platform | Redhat | 4.0 (including) | 4.0 (including) |
| Satellite | Redhat | 6.0 (including) | 6.0 (including) |
| Update_infrastructure | Redhat | 4 (including) | 4 (including) |
| Enterprise_linux | Redhat | 7.0 (including) | 7.0 (including) |
| Enterprise_linux | Redhat | 8.0 (including) | 8.0 (including) |
| Enterprise_linux | Redhat | 9.0 (including) | 9.0 (including) |
| Enterprise_linux | Redhat | 10.0 (including) | 10.0 (including) |
| Red Hat Enterprise Linux 10 | RedHat | libsolv-0:0.7.33-5.el10_2 | * |
| Red Hat Enterprise Linux 10.0 Extended Update Support | RedHat | libsolv-0:0.7.29-8.el10_0.1 | * |
| Red Hat Hardened Images | RedHat | libsolv-main-0.7.38-2.hum1 | * |
| Libsolv | Ubuntu | questing | * |
| Libsolv | Ubuntu | upstream | * |