A flaw was found in libsolv. A stack-based buffer overflow vulnerability exists in the PGP verification component due to incorrect length handling when copying EdDSA 's' MPI into a stack buffer. A remote attacker could craft a malicious Ed25519 PGP signature with mismatched MPI lengths. Processing this crafted signature could lead to a denial of service in automated package or repository processing workflows.
{
"cwe_ids": [
"CWE-121"
],
"cna_assigner": "redhat",
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/48xxx/CVE-2026-48863.json"
}[
{
"id": "CVE-2026-48863-73543eac",
"deprecated": false,
"source": "https://github.com/opensuse/libsolv/commit/44f8c085045b1f771641091bbb2b810d12cff9e8",
"target": {
"file": "ext/solv_pgpvrfy.c"
},
"digest": {
"line_hashes": [
"329850278763516896724822849770523560059",
"142295490632953770221805065423600094178",
"4706000968535030315093977171942802056",
"107972823932981198622960483210413454460"
],
"threshold": 0.9
},
"signature_version": "v1",
"signature_type": "Line"
}
]
"2026-07-19T09:09:25Z"
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-48863.json"