CVE detail
CVE-2026-9150
A flaw was found in libsolv. This stack-based buffer overflow vulnerability occurs in libsolv's Debian metadata parser when processing specially crafted Debian repository metadata. An attacker could exploit this by providing malicious SHA384 or SHA512 checksum tags, leading to memory corruption and a denial of service (DoS) in the affected system.
Buzz score
Why this CVE is surfacing
This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.
Buzz score components · mention 20.8 · diversity 16.5 · KEV 0.0 · OTX 0.0 · PoC 0.0
Why it matters now
Mention timeline
- Total mentions
- 0
- within the 30d window
- Peak daily
- 0
- highest bucket
Evidence
Source links by recency
7 source links · newest first
- CVE-2026-9150 Libsolv: stack-based buffer overflow in libsolv's debian metadata parser when handling sha384/sha512 checksumsMicrosoft MSRC
Information published.
vendormsrc.microsoft.comMay 27, 2026, 8:18 AM No excerpt available.
Exploitgithub.comMay 20, 2026, 11:16 PM- https://bugzilla.redhat.com/show_bug.cgi?id=2460379bugzilla.redhat.com
No excerpt available.
Exploitbugzilla.redhat.comMay 20, 2026, 11:16 PM - https://access.redhat.com/security/cve/CVE-2026-9150access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comMay 20, 2026, 11:16 PM - https://access.redhat.com/errata/RHSA-2026:30649access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comMay 20, 2026, 11:16 PM - https://access.redhat.com/errata/RHSA-2026:28236access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comMay 20, 2026, 11:16 PM - https://access.redhat.com/errata/RHSA-2026:21333access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comMay 20, 2026, 11:16 PM
Exploit code
Public exploit repository references
Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.
0 repository references · best confidence N/A · max 0 stars
Related records
Similar CVEs
6 related CVEs with shared weakness or product evidence
- CVE-2026-48864CVSS 7.8 · High
A flaw was found in libsolv. This heap buffer overflow occurs during the decompression of attacker-controlled compressed data within `.solv` files due to insufficient input valida…
- CVE-2026-9149CVSS 6.5 · Medium
A flaw was found in libsolv. This heap buffer overflow vulnerability occurs when a victim processes a specially crafted `.solv` file containing negative size values in the `repo_a…
- CVE-2025-6170CVSS 2.5 · Low
A flaw was found in the interactive shell of the xmllint command-line tool, used for parsing XML files. When a user inputs an overly long command, the program does not check the i…
- CVE-2026-13757CVSS 6.2 · Medium
A flaw was found in p11-kit. The RPC message attribute parsing functions p11_rpc_message_get_attribute() and p11_rpc_message_get_attribute_array_value() form a mutually-recursive…
- CVE-2026-13595CVSS 6.8 · Medium
A flaw was found in the libblkid library of util-linux. During nested partition probing, the BSD, Minix, Solaris x86, and UnixWare partition probers cache a raw pointer to a paren…
- CVE-2026-55653CVSS 4.3 · Medium
A flaw was found in OpenSSH. A malicious SSH server can exploit a double free vulnerability in the Diffie-Hellman Group Exchange (DH-GEX) client path. This occurs during FIPS (Fed…