Impact
An out‑of‑bounds memory write occurs when libsolv rewrites a .solv cache file, because directory‑id values read from the file’s compressed filelist data are not validated. A corrupted or specially crafted .solv cache file can trigger a crash in tools such as dnf, yum or zypper when they next process the file. This failure results in denial of service for the affected package‑management operation, but does not lead to arbitrary code execution because the out‑of‑bounds write stores a fixed, non‑attacker‑controlled value.
Affected Systems
Red Hat Enterprise Linux 7 through 10, Red Hat Hardened Images, Red Hat OpenShift Container Platform 4, Red Hat Satellite 6, and Red Hat Update Infrastructure 4 for Cloud Providers are affected. The vulnerability is present in the libsolv component used by their RPM‑based package managers; no specific affected versions were listed.
Risk and Exploitability
The CVSS score of 5.5 reflects moderate severity, and the EPSS score is not available, indicating no known high exploitation probability. The issue is not listed in CISA’s KEV catalog, suggesting it is not a known exploited vulnerability. Exploitation would require the attacker to supply or influence a corrupted .solv cache file—typically through an unclean shutdown or by tampering with repository data—so the risk to systems that strictly control repository updates is lower, but systems that rely on automatic package‑manager updates remain susceptible to denial of service.
OpenCVE Enrichment