<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T14:54:13.409045+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/alsa-2026:28236</id>
    <title>ALSA-2026:28236 — Moderate: libsolv security update</title>
    <updated>2026-10-02T14:54:13.431644+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> AlmaLinux:10: libsolv, AlmaLinux:10: libsolv-devel, AlmaLinux:10: libsolv-tools, AlmaLinux:10: libsolv-tools-base, AlmaLinux:10: python3-solv</p>
<p>The libsolv packages provide a library for resolving package dependencies using a satisfiability algorithm.</p>
<p>Security Fix(es):</p>
<p>* libsolv: Stack-based buffer overflow in libsolv's Debian metadata parser when handling SHA384/SHA512 checksums (CVE-2026-9150)
  * libsolv: Heap buffer overflow in libsolv repo_add_solv via negative maxsize from crafted .solv file (CVE-2026-9149)
  * libsolv: Heap buffer overflow in libsolv repopagestore via unchecked decompression of malicious .solv page data (CVE-2026-48864)</p>
<p>For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/alsa-2026:28236"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2026-avi-0693</id>
    <title>certfr-2026-avi-0693 — De multiples vulnérabilités ont été découvertes dans Microsoft Azure Linux. Elles permettent à un attaquant de provoque…</title>
    <updated>2026-10-02T14:54:13.431717+00:00</updated>
    <content>certfr-2026-avi-0693</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2026-avi-0693"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-362211</id>
    <title>EUVD-2026-362211</title>
    <updated>2026-10-02T14:54:13.431737+00:00</updated>
    <content>EUVD-2026-362211</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-362211"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-9150</id>
    <title>fkie_cve-2026-9150</title>
    <updated>2026-10-02T14:54:13.431750+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>A flaw was found in libsolv. This stack-based buffer overflow vulnerability occurs in libsolv's Debian metadata parser when processing specially crafted Debian repository metadata. An attacker could exploit this by providing malicious SHA384 or SHA512 checksum tags, leading to memory corruption and a denial of service (DoS) in the affected system.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-9150"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-p4w9-3pj8-mhq7</id>
    <title>GHSA-p4w9-3pj8-mhq7</title>
    <updated>2026-10-02T14:54:13.431774+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>A flaw was found in libsolv. This stack-based buffer overflow vulnerability occurs in libsolv's Debian metadata parser when processing specially crafted Debian repository metadata. An attacker could exploit this by providing malicious SHA384 or SHA512 checksum tags, leading to memory corruption and a denial of service (DoS) in the affected system.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-p4w9-3pj8-mhq7"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/msrc_cve-2026-9150</id>
    <title>msrc_CVE-2026-9150 — Libsolv: stack-based buffer overflow in libsolv's debian metadata parser when handling sha384/sha512 checksums</title>
    <updated>2026-10-02T14:54:13.431790+00:00</updated>
    <content>msrc_CVE-2026-9150</content>
    <link href="https://cve.radiocsirt.org/vuln/msrc_cve-2026-9150"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2026-2466</id>
    <title>OESA-2026-2466 — libsolv security update</title>
    <updated>2026-10-02T14:54:13.431806+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:20.03-LTS-SP4: libsolv</p>
<p>A free package dependency solver using a satisfiability algorithm. The library is based on two major, but independent, blocks:

Security Fix(es):</p>
<p>A flaw was found in libsolv. This heap buffer overflow vulnerability occurs when a victim processes a specially crafted `.solv` file containing negative size values in the `repo_add_solv` function. This leads to an undersized memory allocation and a subsequent out-of-bounds write. An attacker could exploit this to cause a denial of service (DoS).(CVE-2026-9149)</p>
<p>A flaw was found in libsolv. This stack-based buffer overflow vulnerability occurs in libsolv&amp;apos;s Debian metadata parser when processing specially crafted Debian repository metadata. An attacker could exploit this by providing malicious SHA384 or SHA512 checksum tags, leading to memory corruption and a denial of service (DoS) in the affected system.(CVE-2026-9150)</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2026-2466"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2026:10895-1</id>
    <title>openSUSE-SU-2026:10895-1 — libsolv-demo-0.7.38-1.1 on GA media</title>
    <updated>2026-10-02T14:54:13.431831+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>libsolv-demo-0.7.38-1.1 on GA media</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2026:10895-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2026:21333</id>
    <title>RHSA-2026:21333 — Red Hat Security Advisory: Red Hat Hardened Images RPMs bug fix and enhancement update</title>
    <updated>2026-10-02T14:54:13.431849+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>libsolv: Heap buffer overflow in libsolv repo_add_solv via negative maxsize from crafted .solv file libsolv: Stack-based buffer overflow in libsolv's Debian metadata parser when handling SHA384/SHA512 checksums libsolv: Heap buffer overflow in libsolv repopagestore via unchecked decompression of malicious .solv page data</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2026:21333"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rlsa-2026:28236</id>
    <title>RLSA-2026:28236 — Moderate: libsolv security update</title>
    <updated>2026-10-02T14:54:13.431869+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Rocky Linux:10: libsolv</p>
<p>The libsolv packages provide a library for resolving package dependencies using a satisfiability algorithm.</p>
<p>Security Fix(es):</p>
<p>* libsolv: Stack-based buffer overflow in libsolv's Debian metadata parser when handling SHA384/SHA512 checksums (CVE-2026-9150)</p>
<p>* libsolv: Heap buffer overflow in libsolv repo_add_solv via negative maxsize from crafted .solv file (CVE-2026-9149)</p>
<p>* libsolv: Heap buffer overflow in libsolv repopagestore via unchecked decompression of malicious .solv page data (CVE-2026-48864)</p>
<p>For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rlsa-2026:28236"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2026:21988-1</id>
    <title>SUSE-SU-2026:21988-1 — Security update for libzypp, libsolv</title>
    <updated>2026-10-02T14:54:13.431893+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for libzypp, libsolv</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2026:21988-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-9150</id>
    <title>UBUNTU-CVE-2026-9150</title>
    <updated>2026-10-02T14:54:13.431908+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:Pro:16.04:LTS: libsolv, Ubuntu:Pro:18.04:LTS: libsolv, Ubuntu:20.04:LTS: libsolv, Ubuntu:22.04:LTS: libsolv, Ubuntu:24.04:LTS: libsolv, Ubuntu:25.10: libsolv, Ubuntu:26.04:LTS: libsolv</p>
<p>A flaw was found in libsolv. This stack-based buffer overflow vulnerability occurs in libsolv's Debian metadata parser when processing specially crafted Debian repository metadata. An attacker could exploit this by providing malicious SHA384 or SHA512 checksum tags, leading to memory corruption and a denial of service (DoS) in the affected system.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-9150"/>
  </entry>
</feed>
