CVE-2018-20533: Canonical Ubuntu Linux

Medium severity, CVSS 6.5. EPSS: 2.2% chance of exploitation in the next 30 days.

There is a NULL pointer dereference at ext/testcase.c (function testcase_str2dep_complex) in libsolvext.a in libsolv through 0.7.2 that will cause a denial of service.

Affected products

  • Canonical Ubuntu Linux: version 18.10 only
  • Opensuse Libsolv: up to and including 0.7.2

Published 2018-12-28. Last modified 2026-06-17.