Junglewise Threat Intelligence

CVE-2026-9149: openSUSE libsolv heap buffer overflow in repo_add_solv

CVE-2026-9149 · Severity: medium · CVSS 6.5 · Published 2026-05-21

Technologies: Opensuse Libsolv. Vendors: Opensuse.

Executive brief

libsolv is a library used by package managers (like DNF and Zypper) to resolve software dependencies. A vulnerability exists where processing a maliciously crafted repository file (.solv) can cause the application to crash. This could lead to a denial of service, preventing users or automated systems from installing or updating software.

Technical details

A heap-based buffer overflow exists in libsolv's `repo_add_solv` function due to improper validation of `maxsize` and `allsize` values read from `.solv` file headers. The `read_id` function returns a signed `Id` (int); if a crafted file contains a large unsigned value, it is interpreted as a negative integer. This leads to an integer overflow during buffer size calculation in `solv_calloc`, resulting in an undersized heap allocation. Subsequently, `fread` uses a default `DATA_READ_CHUNK` (8192 bytes) to populate the buffer, causing an out-of-bounds write. The vulnerability is reachable via any application that parses untrusted `.solv` files, such as `dumpsolv`. A fix has been proposed in the openSUSE libsolv GitHub repository (PR #617).

Affected products

  • openSUSE libsolv <= 0.7.36

Timeline

  • 2026-04-21: disclosed: Reported by Aisle Research via Red Hat Bugzilla
  • 2026-04-23: other: Pull request with fix submitted to openSUSE/libsolv GitHub
  • 2026-04-28: patched: Fix merged into libsolv master branch
  • 2026-05-21: advisory: CVE-2026-9149 published in NVD

References

Related threats