REDHAT-BUG-1665532: Null Pointer Dereference
A vulnerability was found in libsolv through 0.7.2. There is a NULL pointer dereference at ext/testcase.c (function testcaseread) in libsolvext.a that will cause a denial of service.
References: https://bugzilla.redhat.com/showbug.cgi?id=1652605
Upstream Patch: https://github.com/openSUSE/libsolv/pull/291
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-1665532?
The severity of REDHAT-BUG-1665532 is classified as a denial of service vulnerability due to a NULL pointer dereference.
How do I fix REDHAT-BUG-1665532?
To fix REDHAT-BUG-1665532, update the libsolv package to a version later than 0.7.2.
Which software is affected by REDHAT-BUG-1665532?
REDHAT-BUG-1665532 affects the openSUSE libsolv package version up to and including 0.7.2.
What causes the vulnerability in REDHAT-BUG-1665532?
The vulnerability in REDHAT-BUG-1665532 is caused by a NULL pointer dereference in the function testcase_read in libsolvext.a.
Is there a known workaround for REDHAT-BUG-1665532?
There is no known workaround for REDHAT-BUG-1665532 other than applying the software update.