CVE-2026-48863
OpenSUSE libsolv, Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 7
A flaw was found in libsolv. A stack-based buffer overflow vulnerability exists in the PGP verification component due to incorrect length handling when copying EdDSA 's' MPI into a stack buffer. A remote attacker could craft a malicious Ed25519 PGP signature with mismatched MPI lengths. Processing this crafted signature could lead to a denial of service in automated package or repository processing workflows.
- CVSS
- 7.5
- EPSS
- 0.47% 38.2% percentile
- CISA KEV
- Not listed
- Published
- 2026.07.16