Skip to content
Red HatCVE-2026-82327

Red Hat libsolv: denial of service

Medium5.5CVE-2026-82327 · Published Aug 28, 2026

A flaw was found in libsolv, a dependency-resolution library used by RPM-based package managers such as dnf and zypper to work with .solv repository cache files. When libsolv rewrites a .solv cache file, it reads directory-id values from the file's compressed filelist data without validating that they fall within the expected range. A corrupted or specially crafted .solv cache file (for example, one left in a torn state after an unclean system shutdown) can cause an out-of-bounds memory write when a tool such as dnf, yum, or zypper next processes it. Successful exploitation is expected to result in a crash of the affected tool (denial of service); it is not expected to allow arbitrary code execution because the out-of-bounds write always stores a fixed, non-attacker-controlled value.

Red Hat advisory

Affected versions

PackageAffectedFixed in
Red Hat Enterprise Linux 10
Product
all versionsNo fix yet
Red Hat Enterprise Linux 7
Product
all versionsNo fix yet
Red Hat Enterprise Linux 8
Product
all versionsNo fix yet
Red Hat Enterprise Linux 9
Product
all versionsNo fix yet
Red Hat Hardened Images
Product
all versionsNo fix yet
Red Hat OpenShift Container Platform 4
Product
all versionsNo fix yet
Red Hat Satellite 6
Product
all versionsNo fix yet
all versionsNo fix yet
all versionsNo fix yet
all versionsNo fix yet
Red Hat Update Infrastructure 4 for Cloud Providers
Product
all versionsNo fix yet
Details and references
CVSS 3.1
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Severity from
the vendor (its own CVE record or advisory)
Weakness
CWE-129

More Red Hat advisories

All Red Hat
Advisory
Red Hat file-psd plugin: out-of-bounds read
Medium6.1Aug 28
Red Hat file-ico plugin: out-of-bounds read
Medium6.1Aug 28
Red Hat file-pvr plugin: out-of-bounds read
Medium6.1Aug 28
Red Hat GIMP: denial of service
Medium6.1Aug 28
Red Hat FFmpeg: denial of service
Medium5.4Aug 28
Red Hat Ansible Automation Platform 2: resource exhaustion
Medium5.9Aug 28

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.