Security update for libsolv, libzypp, zypper
This security update addresses multiple vulnerabilities in libsolv, libzypp, and zypper components used by SUSE. The fixed issues include heap and stack-based buffer overflows, path traversal vulnerabilities, and arbitrary local file overwrite risks caused by crafted repository metadata or malformed files. The update also improves robustness against malformed repository data and enforces restrictions on repository path entries to prevent directory traversal outside allowed locations. These fixes mitigate potential crashes, memory corruption, and unauthorized file modifications.
AI Analysis
Technical Summary
The update for libsolv, libzypp, and zypper resolves seven distinct vulnerabilities: CVE-2026-9149 (heap buffer overflow via negative maxsize in .solv files), CVE-2026-9150 (stack buffer overflow in Debian metadata parser handling SHA384/SHA512 checksums), CVE-2026-25707 (arbitrary local file overwrite via crafted repo metadata), CVE-2026-44933 (prevention of script escape from signature verification directory), CVE-2026-44941 and CVE-2026-44942 (path traversal via 'keyhint' and .repo file path entries), and CVE-2026-48863 (buffer overflow parsing EdDSA signatures). The libzypp component was updated to version 17.38.13 with enhanced validation to disallow repo paths outside the base URL and discard metadata entries that would reference locations outside the local cache. libsolv was updated to version 0.7.39 with improved robustness against corrupt files and added limit checks to prevent overflows. These changes collectively improve security by preventing memory corruption, unauthorized file writes, and path traversal attacks in repository handling.
Potential Impact
Exploitation of these vulnerabilities could lead to memory corruption (heap and stack buffer overflows), application crashes, and unauthorized overwriting of local files. Path traversal issues could allow attackers to access or modify files outside intended directories. These vulnerabilities affect the integrity and stability of package management operations, potentially enabling local attackers to compromise system security or disrupt package management processes.
Mitigation Recommendations
An official security update is available that addresses all listed vulnerabilities. Users should apply the update to libsolv, libzypp, and zypper as provided by the SUSE Product Security Team. The update enforces path restrictions, sanitizes repository metadata, and fixes buffer overflow conditions. No additional mitigation steps are required beyond applying the official update.
Security update for libsolv, libzypp, zypper
Description
This security update addresses multiple vulnerabilities in libsolv, libzypp, and zypper components used by SUSE. The fixed issues include heap and stack-based buffer overflows, path traversal vulnerabilities, and arbitrary local file overwrite risks caused by crafted repository metadata or malformed files. The update also improves robustness against malformed repository data and enforces restrictions on repository path entries to prevent directory traversal outside allowed locations. These fixes mitigate potential crashes, memory corruption, and unauthorized file modifications.
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The update for libsolv, libzypp, and zypper resolves seven distinct vulnerabilities: CVE-2026-9149 (heap buffer overflow via negative maxsize in .solv files), CVE-2026-9150 (stack buffer overflow in Debian metadata parser handling SHA384/SHA512 checksums), CVE-2026-25707 (arbitrary local file overwrite via crafted repo metadata), CVE-2026-44933 (prevention of script escape from signature verification directory), CVE-2026-44941 and CVE-2026-44942 (path traversal via 'keyhint' and .repo file path entries), and CVE-2026-48863 (buffer overflow parsing EdDSA signatures). The libzypp component was updated to version 17.38.13 with enhanced validation to disallow repo paths outside the base URL and discard metadata entries that would reference locations outside the local cache. libsolv was updated to version 0.7.39 with improved robustness against corrupt files and added limit checks to prevent overflows. These changes collectively improve security by preventing memory corruption, unauthorized file writes, and path traversal attacks in repository handling.
Potential Impact
Exploitation of these vulnerabilities could lead to memory corruption (heap and stack buffer overflows), application crashes, and unauthorized overwriting of local files. Path traversal issues could allow attackers to access or modify files outside intended directories. These vulnerabilities affect the integrity and stability of package management operations, potentially enabling local attackers to compromise system security or disrupt package management processes.
Mitigation Recommendations
An official security update is available that addresses all listed vulnerabilities. Users should apply the update to libsolv, libzypp, and zypper as provided by the SUSE Product Security Team. The update enforces path restrictions, sanitizes repository metadata, and fixes buffer overflow conditions. No additional mitigation steps are required beyond applying the official update.
Technical Details
- Gcve Source
- db.gcve.eu
- Csaf Category
- csaf_security_advisory
- Csaf Version
- 2.0
- Publisher
- SUSE Product Security Team
- Advisory Id
- SUSE-SU-2026:2590-1
- Cve Count
- 7
- Additional Cves
- ["CVE-2026-44933","CVE-2026-44941","CVE-2026-44942","CVE-2026-48863","CVE-2026-9149","CVE-2026-9150"]
- Cvss Version
- null
Threat ID: 6a3c0d28eed863c81e23f1ca
Added to database: 06/24/2026, 17:00:24 UTC
Last enriched: 06/24/2026, 17:22:21 UTC
Last updated: 06/24/2026, 18:27:22 UTC
Views: 6
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.