First published: Mon Feb 21 2022(Updated: )
Two heap-overflow vulnerabilities exist in openSUSE/libsolv libsolv through 13 Dec 2020 in the decisionmap variable via the resolve_dependencies function at src/solver.c (line 1940 & line 1995), which could cause a remote Denial of Service.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/libsolv | <0.7.17 | 0.7.17 |
Opensuse Libsolv | <0.7.17 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-44568 is a vulnerability that exists in openSUSE/libsolv libsolv through 13 Dec 2020, which could cause a remote Denial of Service.
CVE-2021-44568 has a severity keyword of 'medium' and a severity value of 6.5.
The affected software is openSUSE/libsolv libsolv version up to 0.7.17.
To fix CVE-2021-44568, update the openSUSE/libsolv libsolv package to version 0.7.17 or higher.
Additional information about CVE-2021-44568 can be found in the references: https://github.com/yangjiageng/PoC/blob/master/libsolv-PoCs/resolve_dependencies-1940, https://github.com/yangjiageng/PoC/blob/master/libsolv-PoCs/resolve_dependencies-1995, https://github.com/openSUSE/libsolv/issues/425