CVE-2021-44568: Medium severity openSUSE libsolv vulnerability
Two heap-overflow vulnerabilities exist in openSUSE/libsolv libsolv through 13 Dec 2020 in the decisionmap variable via the resolvedependencies function at src/solver.c (line 1940 & line 1995), which could cause a remote Denial of Service.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2021-44568?
CVE-2021-44568 is a vulnerability that exists in openSUSE/libsolv libsolv through 13 Dec 2020, which could cause a remote Denial of Service.
How severe is CVE-2021-44568?
CVE-2021-44568 has a severity keyword of 'medium' and a severity value of 6.5.
Which software is affected by CVE-2021-44568?
The affected software is openSUSE/libsolv libsolv version up to 0.7.17.
How can CVE-2021-44568 be fixed?
To fix CVE-2021-44568, update the openSUSE/libsolv libsolv package to version 0.7.17 or higher.
Is there any additional information available for CVE-2021-44568?
Additional information about CVE-2021-44568 can be found in the references: https://github.com/yangjiageng/PoC/blob/master/libsolv-PoCs/resolve_dependencies-1940, https://github.com/yangjiageng/PoC/blob/master/libsolv-PoCs/resolve_dependencies-1995, https://github.com/openSUSE/libsolv/issues/425