CVEFinder.io

CVE-2026-9149

đŸ”ļ medium
🔍 Scan for this CVE
Summary

A flaw was found in libsolv. This heap buffer overflow vulnerability occurs when a victim processes a specially crafted `.solv` file containing negative size values in the `repo_add_solv` function. This leads to an undersized memory allocation and a subsequent out-of-bounds write. An attacker could exploit this to cause a denial of service (DoS).

CVSS Score
6.5
Medium
EPSS Score
0.3
Exploit Probability
Published Date
2026-05-21
First Seen: 2026-05-21
📊 Relative Risk Intelligence

This CVE is Lower Risk - more severe than 47.7% of all 336,041 vulnerabilities in our database.

#175,688
Below average severity
Severity Percentile
đŸŽ¯ CISA SSVC Assessment Updated: May 21, 2026
🔍 Exploitation Status
Poc
Proof-of-concept available
âš™ī¸ Automatable
NO
Requires human interaction
đŸ’Ĩ Technical Impact
Partial
Limited system impact
🏆 Discovered By
This issue was discovered by AISLE in partnership with Red Hat.
SSVC data provided by CISA
Last Modified 2026-06-27
CVSS Vector 3.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
CWE IDs (Weakness Types)

đŸ“Ļ Affected Products 8

🔗 References 5

🔗 Related CVEs 6

CVE ID Severity CVSS EPSS Summary Published
CVE-2026-15041 â„šī¸ low 3.7 0.3 A flaw was found in 389 Directory Server. The PBKDF2-SHA256 password verification function uses standard memcmp() for co... 2026-07-08
CVE-2026-58384 âš ī¸ high 7.3 0.2 A flaw was found in GIMP's PSD parser. An integer overflow in read_RLE_channel() can cause an undersized heap allocation... 2026-07-07
CVE-2026-14940 đŸ”ļ medium 5.3 0.3 A heap-buffer-overflow flaw was found in 389 Directory Server (389-ds-base). When normalizing a Distinguished Name (DN) ... 2026-07-07
CVE-2026-14969 đŸ”ļ medium 4.4 0.1 A flaw was found in 389-ds-base where the LDBM backend attribute encryption uses a hardcoded static initialization vecto... 2026-07-07
CVE-2026-58380 âš ī¸ high 7.3 0.2 A flaw was found in GIMP's PNM file format parser. When parsing a specially crafted PNM file, the pnmscanner_gettoken() ... 2026-07-06
CVE-2026-59089 đŸ”ļ medium 5.5 0.2 A flaw was found in GIMP. The PlayStation TIM loader, responsible for handling PlayStation image files, incorrectly calc... 2026-07-06
These CVEs affect the same products