Import Source
https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-88053.json
JSON Data
https://api.osv.dev/v1/vulns/AZL-88053
Upstream
Published
2026-05-20T23:16:36Z
Modified
2026-08-30T05:26:50Z
Summary
CVE-2026-9150 affecting package libsolv for versions less than 0.7.28-4
Details

A flaw was found in libsolv. This stack-based buffer overflow vulnerability occurs in libsolv's Debian metadata parser when processing specially crafted Debian repository metadata. An attacker could exploit this by providing malicious SHA384 or SHA512 checksum tags, leading to memory corruption and a denial of service (DoS) in the affected system.

References

Affected packages

Azure Linux:3 / libsolv

Package

Name
libsolv
Purl
pkg:rpm/azure-linux/libsolv

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
0.7.28-4

Database specific

source
"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-88053.json"