Skip to main content
EPSS 0.6%top 53%

Security update for zypper, libzypp, libsolv

0
High
Published: 06/19/2026 (06/19/2026, 07:35:00 UTC)
Source: GCVE Database
Vendor/Project: SUSE Product Security Team
Product: SUSE

Description

This update for zypper, libzypp, libsolv fixes the following issues: Changes in zypper: Update to 1.14.98: - Transactional systems: Delegate rw-commands to transactional-wrapper if available (jsc#PED-13680, jsc#PED-15607) On a transactional system where the root filesystem is mounted read-only, zypper commands that modify the system cannot be executed directly. If the system provides a transactional-wrapper utility, zypper will automatically attempt to invoke it. The wrapper transparently executes the zypper command within a new, writable snapshot and manages the lifecycle of that snapshot based on the command's exit status. On transactional systems lacking a transactional-wrapper, users must manually invoke specialized tools -such as transactional-update- to install, update, or remove software. - Add --filter-version-change to zypper lu. Adds filtering by version change significance to reduce noise in update listings. Supports levels: rebuild (hides rebuild-only changes) and package (hides all release-only changes). - Autorefresh ris-services the way as plugin-services (bsc#1246504) It's actually wrong to treat service refreshes different depending on the service type. For the purpose of a service it makes no difference how the data about the repos to use are acquired. Changes in libzypp: Updated to 17.38.13: - A .repo files "path=" entry must not refer to a location outside the repo (bsc#1267874, CVE-2026-44942) A "path=" entry may solely denote a sub-directory of the baseurl where the metadata are located. A relative path trying to access data outside the baseurl is reported and sanitized. - Repo "keyhint" must denote a filename, no path (bsc#1267426, CVE-2026-44941) - Fix potential crash on malformed or malicious repository metadata (fixes #740) - Repo metadata: discard entries referring to a location outside the repo (bsc#1259802, CVE-2026-25707) Mirroring those data locally would refer to a location outside the repo's local cache directory. Those data entries are reported and discarded. - zypp.conf: Allow [env] section to add environment variables. This feature is designed to enable environment-specific settings or debugging options over an extended period. See zypp.conf(5). - Prevent configured scripts from escaping the sigcheck directory (bsc#1265223, CVE-2026-44933) - StringV: guard hasPrefix/hasPrefixCI against reading past the view end (fixes #735) - Mandatory signature verification plugin support (PED#11922) - Fix purge-kernel -rc kernel handling (bsc#1239718) - Explicitly_set_pool_DISTTYPE_RPM (fixes #726) - Check for trusted key updates when updating the general keyring (bsc#1259706) - Support multiple MirroredOrigin authorities (bsc#1253193) - Workaround doxygen bug: doxygen/doxygen#12057 - libzypp.spec: Add missing graphviz-gd BuildRequires (boo#1259842) Changes in libsolv: Updated to 0.7.39: - fix solv_chksum_free segfault when called with a NULL pointer - made repo_add_solv more robust against corrupt files [bsc#1265935] [CVE-2026-9149] - fix potential buffer overflow when verifying EdDSA signatures [bsc#1266039] [CVE-2026-48863] - added limit checks in multiple places to catch overflows - reduce the size of the language id cache - fixed Debian canon selection - fixed dbpath detection in repo_rpmdb_librpm - reduced stack usage in repo page compression (needed for musl) - fix parsing of sha512 checksums in debian repositories [bsc#1265938] [CVE-2026-9150] - improve speed of dirpool_add_dir makeing parsing of filelists.xml twice as fast - fix parsing of recommends in the old Mandriva synthesis format

Affected software

suse/libzypp
pkg:rpm/suse/libzypp
Affected versions
<17.38.13
suse/libsolv
pkg:rpm/suse/libsolv
Affected versions
<0.7.39

Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 06/24/2026, 17:22:21 UTC

Technical Analysis

The update for libsolv, libzypp, and zypper resolves seven distinct vulnerabilities: CVE-2026-9149 (heap buffer overflow via negative maxsize in .solv files), CVE-2026-9150 (stack buffer overflow in Debian metadata parser handling SHA384/SHA512 checksums), CVE-2026-25707 (arbitrary local file overwrite via crafted repo metadata), CVE-2026-44933 (prevention of script escape from signature verification directory), CVE-2026-44941 and CVE-2026-44942 (path traversal via 'keyhint' and .repo file path entries), and CVE-2026-48863 (buffer overflow parsing EdDSA signatures). The libzypp component was updated to version 17.38.13 with enhanced validation to disallow repo paths outside the base URL and discard metadata entries that would reference locations outside the local cache. libsolv was updated to version 0.7.39 with improved robustness against corrupt files and added limit checks to prevent overflows. These changes collectively improve security by preventing memory corruption, unauthorized file writes, and path traversal attacks in repository handling.

Potential Impact

Exploitation of these vulnerabilities could lead to memory corruption (heap and stack buffer overflows), application crashes, and unauthorized overwriting of local files. Path traversal issues could allow attackers to access or modify files outside intended directories. These vulnerabilities affect the integrity and stability of package management operations, potentially enabling local attackers to compromise system security or disrupt package management processes.

Mitigation Recommendations

An official security update is available that addresses all listed vulnerabilities. Users should apply the update to libsolv, libzypp, and zypper as provided by the SUSE Product Security Team. The update enforces path restrictions, sanitizes repository metadata, and fixes buffer overflow conditions. No additional mitigation steps are required beyond applying the official update.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Csaf Category
csaf_security_advisory
Csaf Version
2.0
Publisher
SUSE Product Security Team
Advisory Id
SUSE-SU-2026:2590-1
Cve Count
7
Additional Cves
["CVE-2026-44933","CVE-2026-44941","CVE-2026-44942","CVE-2026-48863","CVE-2026-9149","CVE-2026-9150"]

Threat ID: 6a3c0d28eed863c81e23f1ca

Added to database: 06/24/2026, 17:00:24 UTC

Last enriched: 06/24/2026, 17:22:21 UTC

Last updated: 09/22/2026, 02:49:14 UTC

Views: 146

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses