Improper Validation of Array Index Affecting libsolv-devel package, versions *


Severity

Recommended
0.0
medium
0
10

Based on CentOS security rating.

Threat Intelligence

EPSS
0.11% (2nd percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-CENTOS8-LIBSOLVDEVEL-19428272
  • published29 Aug 2026
  • disclosed28 Aug 2026

Introduced: 28 Aug 2026

NewCVE-2026-82327  (opens in a new tab)
CWE-129  (opens in a new tab)

How to fix?

There is no fixed version for Centos:8 libsolv-devel.

NVD Description

Note: Versions mentioned in the description apply only to the upstream libsolv-devel package and not the libsolv-devel package as distributed by Centos. See How to fix? for Centos:8 relevant fixed versions and status.

A flaw was found in libsolv, a dependency-resolution library used by RPM-based package managers such as dnf and zypper to work with .solv repository cache files. When libsolv rewrites a .solv cache file, it reads directory-id values from the file's compressed filelist data without validating that they fall within the expected range. A corrupted or specially crafted .solv cache file (for example, one left in a torn state after an unclean system shutdown) can cause an out-of-bounds memory write when a tool such as dnf, yum, or zypper next processes it. Successful exploitation is expected to result in a crash of the affected tool (denial of service); it is not expected to allow arbitrary code execution because the out-of-bounds write always stores a fixed, non-attacker-controlled value.

CVSS Base Scores

version 3.1