{"id":"AZL-88056","summary":"CVE-2026-9149 affecting package libsolv for versions less than 0.7.28-4","details":"A flaw was found in libsolv. This heap buffer overflow vulnerability occurs when a victim processes a specially crafted `.solv` file containing negative size values in the `repo_add_solv` function. This leads to an undersized memory allocation and a subsequent out-of-bounds write. An attacker could exploit this to cause a denial of service (DoS).","modified":"2026-08-30T05:26:50Z","published":"2026-05-21T00:16:35Z","upstream":["CVE-2026-9149"],"references":[{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-9149"}],"affected":[{"package":{"name":"libsolv","ecosystem":"Azure Linux:3","purl":"pkg:rpm/azure-linux/libsolv"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0.7.28-4"}]}],"database_specific":{"source":"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-88056.json"}}],"schema_version":"1.9.0"}