<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/"><channel><title>Libsolv on ZX Cloud Security</title><link>https://zxcloudsecurity.co.uk/tags/libsolv/</link><description>Recent content in Libsolv on ZX Cloud Security</description><generator>Hugo</generator><language>en-GB</language><lastBuildDate>Thu, 04 Jun 2026 08:45:36 +0000</lastBuildDate><atom:link href="https://zxcloudsecurity.co.uk/tags/libsolv/index.xml" rel="self" type="application/rss+xml"/><item><title>CVE-2026-9149: Libsolv Heap Buffer Overflow in Azure</title><link>https://zxcloudsecurity.co.uk/posts/cve-2026-9149-libsolv-heap-buffer-overflow-azure/</link><pubDate>Thu, 04 Jun 2026 08:45:36 +0000</pubDate><guid>https://zxcloudsecurity.co.uk/posts/cve-2026-9149-libsolv-heap-buffer-overflow-azure/</guid><description>CVE-2026-9149 is a heap buffer overflow in libsolv triggered by a crafted .solv file. Learn the impact on Azure Linux workloads and how to remediate.</description><content:encoded><![CDATA[<p>🟠 <strong>High</strong>  |  <strong>Source:</strong> <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-9149">Microsoft Security Response Center</a></p>
<hr>
<p>CVE-2026-9149 is a heap buffer overflow vulnerability in libsolv, an open-source dependency resolver library used in Linux package management. The flaw can be triggered by a specially crafted .solv file that supplies a negative maxsize value, causing memory corruption in the repo_add_solv function. This matters because libsolv is widely used in Linux-based environments, including Azure workloads, and memory corruption bugs of this nature can potentially lead to arbitrary code execution.</p>
<blockquote>
<p><strong>Architect&rsquo;s Take:</strong> Identify any Azure-hosted Linux workloads, containers, or pipelines that use libsolv or package managers dependent on it (such as zypper or libdnf), and prioritise patching to the fixed version. Additionally, restrict the ingestion of untrusted .solv files within your build and dependency management pipelines to reduce attack surface.</p>
</blockquote>
<p><strong>Original advisory:</strong> <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-9149">CVE-2026-9149 Libsolv: heap buffer overflow in libsolv repo_add_solv via negative maxsize from crafted .solv file</a></p>
]]></content:encoded></item><item><title>CVE-2026-9150: Libsolv Buffer Overflow in Azure</title><link>https://zxcloudsecurity.co.uk/posts/cve-2026-9150-libsolv-stack-buffer-overflow-azure-debian-metadata/</link><pubDate>Thu, 04 Jun 2026 08:45:29 +0000</pubDate><guid>https://zxcloudsecurity.co.uk/posts/cve-2026-9150-libsolv-stack-buffer-overflow-azure-debian-metadata/</guid><description>CVE-2026-9150 is a stack-based buffer overflow in libsolv&amp;#39;s Debian metadata parser affecting SHA-384/SHA-512 checksums. Learn the Azure security impact and</description><content:encoded><![CDATA[<p>🟠 <strong>High</strong>  |  <strong>Source:</strong> <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-9150">Microsoft Security Response Center</a></p>
<hr>
<p>CVE-2026-9150 is a stack-based buffer overflow vulnerability in libsolv, an open-source dependency resolution library, specifically within its Debian metadata parser when processing SHA-384 or SHA-512 checksums. An attacker who can supply malicious package metadata could potentially trigger the overflow to execute arbitrary code or crash affected services. This vulnerability is relevant to Azure environments that rely on libsolv for package management operations, such as those running Linux-based workloads or services that consume package repositories.</p>
<blockquote>
<p><strong>Architect&rsquo;s Take:</strong> Identify any Azure Linux VMs, container images, or managed services (such as Azure Kubernetes Service nodes) that use libsolv for dependency resolution, and prioritise patching to the remediated version. In the interim, consider restricting access to untrusted or external package repositories to reduce exposure.</p>
</blockquote>
<p><strong>Original advisory:</strong> <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-9150">CVE-2026-9150 Libsolv: stack-based buffer overflow in libsolv&rsquo;s debian metadata parser when handling sha384/sha512 checksums</a></p>
]]></content:encoded></item></channel></rss>