A free package dependency solver using a satisfiability algorithm. The library is based on two major, but independent, blocks:
Security Fix(es):
A flaw was found in libsolv. A stack-based buffer overflow vulnerability exists in the PGP verification component due to incorrect length handling when copying EdDSA 's' MPI into a stack buffer. A remote attacker could craft a malicious Ed25519 PGP signature with mismatched MPI lengths. Processing this crafted signature could lead to a denial of service in automated package or repository processing workflows.(CVE-2026-48863)
{
"severity": "High"
}{
"src": [
"libsolv-0.7.14-10.oe2003sp4.src.rpm"
],
"x86_64": [
"libsolv-0.7.14-10.oe2003sp4.x86_64.rpm",
"libsolv-debuginfo-0.7.14-10.oe2003sp4.x86_64.rpm",
"libsolv-debugsource-0.7.14-10.oe2003sp4.x86_64.rpm",
"libsolv-devel-0.7.14-10.oe2003sp4.x86_64.rpm",
"perl-solv-0.7.14-10.oe2003sp4.x86_64.rpm",
"python3-solv-0.7.14-10.oe2003sp4.x86_64.rpm",
"ruby-solv-0.7.14-10.oe2003sp4.x86_64.rpm"
],
"aarch64": [
"libsolv-0.7.14-10.oe2003sp4.aarch64.rpm",
"libsolv-debuginfo-0.7.14-10.oe2003sp4.aarch64.rpm",
"libsolv-debugsource-0.7.14-10.oe2003sp4.aarch64.rpm",
"libsolv-devel-0.7.14-10.oe2003sp4.aarch64.rpm",
"perl-solv-0.7.14-10.oe2003sp4.aarch64.rpm",
"python3-solv-0.7.14-10.oe2003sp4.aarch64.rpm",
"ruby-solv-0.7.14-10.oe2003sp4.aarch64.rpm"
],
"noarch": [
"libsolv-help-0.7.14-10.oe2003sp4.noarch.rpm"
]
}