Red HatCVE-2026-48863
Red Hat libsolv: stack buffer overflow
High7.5CVE-2026-48863 · Published Jul 16, 2026 · updated Aug 31, 2026
A flaw was found in libsolv. A stack-based buffer overflow vulnerability exists in the PGP verification component due to incorrect length handling when copying EdDSA 's' MPI into a stack buffer. A remote attacker could craft a malicious Ed25519 PGP signature with mismatched MPI lengths. Processing this crafted signature could lead to a denial of service in automated package or repository processing workflows.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| Red Hat Enterprise Linux 10 Product | all versions | No fix yet |
| all versions | No fix yet | |
| Red Hat Enterprise Linux 7 Product | all versions | No fix yet |
| all versions | No fix yet | |
| Red Hat Enterprise Linux 8 Product | all versions | No fix yet |
| Red Hat Enterprise Linux 9 Product | all versions | No fix yet |
| Red Hat Hardened Images Product | all versions | No fix yet |
| Red Hat OpenShift Container Platform 4 Product | all versions | No fix yet |
| all versions | No fix yet | |
| Red Hat Satellite 6 Product | all versions | No fix yet |
| Red Hat Update Infrastructure 4 for Cloud Providers Product | all versions | No fix yet |
| libsolv Product | >= 0.6.4, < 0.7.38 | 0.7.38 |
Details and references
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
- Severity from
- the vendor (its own CVE record or advisory)
- Weakness
- CWE-121
- www.cve.org/CVERecord?id=CVE-2026-48863
- nvd.nist.gov/vuln/detail/CVE-2026-48863
- access.redhat.com/security/cve/CVE-2026-48863
- bugzilla.redhat.com/show_bug.cgi?id=2460975
- github.com/openSUSE/libsolv/commit/44f8c085045b1f771641091bbb2b810d12cff9e8#diff-309f245ec9b669ec78b8159c39e6f50130b4d4a0448f742685f7833d04bc4caaR592
- security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-48863.json
More Red Hat advisories
All Red Hat| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Jul 16 | Red Hat Data Grid 8: insecure direct object reference | Medium4.3 | No fix yet |
| Jul 16 | Red Hat PipeWire: code execution | High8.8 | No fix yet |
| Jul 16 | Red Hat Keycloak.: improper access control | High8.1 | 26.5.3 |
| Jul 16 | Red Hat Feast Feature Server: denial of service | High7.5 | 0.59.0 |
| Jul 15 | Red Hat AAP Gateway Envoy proxy configuration: authentication bypass by spoofing | High8.2 | No fix yet |
| Jul 15 | Red Hat samba: denial of service | Medium6.1 | No fix yet |