A flaw was found in libsolv. A stack-based buffer overflow vulnerability exists in the PGP verification component due to incorrect length handling when copying EdDSA 's' MPI into a stack buffer. A re…
高危 CVSS 7.5
摘要
A flaw was found in libsolv. A stack-based buffer overflow vulnerability exists in the PGP verification component due to incorrect length handling when copying EdDSA 's' MPI into a stack buffer. A remote attacker could craft a malicious Ed25519 PGP signature with mismatched MPI lengths. Processing this crafted signature could lead to a denial of service in automated package or repository processing workflows.
中文摘要建设中,暂以英文摘要呈现(DR-003 v2)。
深度研判 · 自动通道
该漏洞尚未生成深度研判报告(DR-003 v2 AI pipeline 建设中)。
数据来源
- NVD DATABASE
原始链接
- https://access.redhat.com/security/cve/CVE-2026-48863
- https://bugzilla.redhat.com/show_bug.cgi?id=2460975
- https://github.com/openSUSE/libsolv/commit/44f8c085045b1f771641091bbb2b810d12cff9e8#diff-309f245ec9b669ec78b8159c39e6f50130b4d4a0448f742685f7833d04bc4caaR592
- https://access.redhat.com/security/cve/CVE-2026-48863
- https://bugzilla.redhat.com/show_bug.cgi?id=2460975
- https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-48863.json
时间线
- nvd_ingest NVD