Buffer overflow vulnerability in function pool_installable in src/repo.h in libsolv before 0.7.17 allows attackers to cause a Denial of Service. Reference: https://github.com/openSUSE/libsolv/issues/417
Created libsolv tracking bugs for this issue: Affects: fedora-all [bug 2000700]
Upstream Patch: https://github.com/openSUSE/libsolv/commit/0077ef29eb46d2e1df2f230fc95a1d9748d49dec
This issue has been addressed in the following products: Red Hat Enterprise Linux 8 Via RHSA-2021:4060 https://access.redhat.com/errata/RHSA-2021:4060
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s): https://access.redhat.com/security/cve/cve-2021-33928
This issue has been addressed in the following products: Red Hat Satellite 6.11 for RHEL 7 Red Hat Satellite 6.11 for RHEL 8 Via RHSA-2022:5498 https://access.redhat.com/errata/RHSA-2022:5498