Executive brief
libsolv is a library used by package managers (like DNF and Zypper) to resolve software dependencies. A vulnerability exists where processing a maliciously crafted repository file (.solv) can cause the application to crash. This could lead to a denial of service, preventing users or automated systems from installing or updating software.
Technical details
A heap-based buffer overflow exists in libsolv's `repo_add_solv` function due to improper validation of `maxsize` and `allsize` values read from `.solv` file headers. The `read_id` function returns a signed `Id` (int); if a crafted file contains a large unsigned value, it is interpreted as a negative integer. This leads to an integer overflow during buffer size calculation in `solv_calloc`, resulting in an undersized heap allocation. Subsequently, `fread` uses a default `DATA_READ_CHUNK` (8192 bytes) to populate the buffer, causing an out-of-bounds write. The vulnerability is reachable via any application that parses untrusted `.solv` files, such as `dumpsolv`. A fix has been proposed in the openSUSE libsolv GitHub repository (PR #617).
Affected products
- openSUSE libsolv <= 0.7.36
Timeline
- 2026-04-21: disclosed: Reported by Aisle Research via Red Hat Bugzilla
- 2026-04-23: other: Pull request with fix submitted to openSUSE/libsolv GitHub
- 2026-04-28: patched: Fix merged into libsolv master branch
- 2026-05-21: advisory: CVE-2026-9149 published in NVD