Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-48863— Libsolv: stack-based buffer overflow in libsolv eddsa pgp signature verification allows denial of service

CVSS 7.5 · High EPSS 0.81% · P53

Possible ATT&CK Techniques 1AI

T1190 · Exploit Public-Facing Application
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2026-48863

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Libsolv: stack-based buffer overflow in libsolv eddsa pgp signature verification allows denial of service
Source: NVD (National Vulnerability Database)
Vulnerability Description
A flaw was found in libsolv. A stack-based buffer overflow vulnerability exists in the PGP verification component due to incorrect length handling when copying EdDSA 's' MPI into a stack buffer. A remote attacker could craft a malicious Ed25519 PGP signature with mismatched MPI lengths. Processing this crafted signature could lead to a denial of service in automated package or repository processing workflows.
Source: NVD (National Vulnerability Database)
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Source: NVD (National Vulnerability Database)
Vulnerability Type
栈缓冲区溢出
Source: NVD (National Vulnerability Database)
Vulnerability Title
openSUSE libsolv 缓冲区错误漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
openSUSE libsolv是openSUSE社区开源的一个检查软件包依赖的库。 openSUSE libsolv 0.7.38之前版本存在缓冲区错误漏洞,该漏洞源于PGP验证组件中复制EdDSA 's' MPI到堆栈缓冲区时长度处理不正确,存在栈缓冲区溢出漏洞,远程攻击者可制作恶意Ed25519 PGP签名,通过处理特制签名导致自动包或仓库处理工作流中的拒绝服务。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
OpenSUSElibsolv 0.6.4 ~ 0.7.38 -
Red HatRed Hat Enterprise Linux 10-cpe:/o:redhat:enterprise_linux:10
Red HatRed Hat Enterprise Linux 7-cpe:/o:redhat:enterprise_linux:7
Red HatRed Hat Enterprise Linux 8-cpe:/o:redhat:enterprise_linux:8
Red HatRed Hat Enterprise Linux 9-cpe:/o:redhat:enterprise_linux:9
Red HatRed Hat Hardened Images-cpe:/a:redhat:hummingbird:1
Red HatRed Hat OpenShift Container Platform 4-cpe:/a:redhat:openshift:4
Red HatRed Hat Satellite 6-cpe:/a:redhat:satellite:6
Red HatRed Hat Update Infrastructure 4 for Cloud Providers-cpe:/a:redhat:rhui:4::el8

II. Public POCs for CVE-2026-48863

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium
Qwen3.6-35B-A3B · 9404 chars
Pro+ exclusive includes:
Vulnerability reproduction recording (real sandbox build + trigger, exclusive)
In-depth vulnerability mechanism
Trigger conditions & impact
Full executable POC code
Exploit chain & mitigation
POC zip download
100+ AI POC generations per month

III. Intelligence Information for CVE-2026-48863

登录查看更多情报信息。

Patches & Fixes for CVE-2026-48863 (1)

Vendor Advisories for CVE-2026-48863 (2)

IV. Related Vulnerabilities

V. Comments for CVE-2026-48863

No comments yet


Leave a comment