Import Source
https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-92388.json
JSON Data
https://api.osv.dev/v1/vulns/AZL-92388
Upstream
Published
2026-07-16T01:16:30Z
Modified
2026-08-30T05:26:50Z
Summary
CVE-2026-48863 affecting package libsolv for versions less than 0.7.28-5
Details

A flaw was found in libsolv. A stack-based buffer overflow vulnerability exists in the PGP verification component due to incorrect length handling when copying EdDSA 's' MPI into a stack buffer. A remote attacker could craft a malicious Ed25519 PGP signature with mismatched MPI lengths. Processing this crafted signature could lead to a denial of service in automated package or repository processing workflows.

References

Affected packages

Azure Linux:3 / libsolv

Package

Name
libsolv
Purl
pkg:rpm/azure-linux/libsolv

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
0.7.28-5

Database specific

source
"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-92388.json"