{"id":"AZL-92388","summary":"CVE-2026-48863 affecting package libsolv for versions less than 0.7.28-5","details":"A flaw was found in libsolv. A stack-based buffer overflow vulnerability exists in the PGP verification component due to incorrect length handling when copying EdDSA 's' MPI into a stack buffer. A remote attacker could craft a malicious Ed25519 PGP signature with mismatched MPI lengths. Processing this crafted signature could lead to a denial of service in automated package or repository processing workflows.","modified":"2026-08-31T05:26:27Z","published":"2026-07-16T01:16:30Z","upstream":["CVE-2026-48863"],"references":[{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-48863"}],"affected":[{"package":{"name":"libsolv","ecosystem":"Azure Linux:3","purl":"pkg:rpm/azure-linux/libsolv"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0.7.28-5"}]}],"database_specific":{"source":"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-92388.json"}}],"schema_version":"1.9.0"}