Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…

Security update for libsolv, libzypp, zypper

0
High
Published: 06/23/2026 (06/23/2026, 14:09:32 UTC)
Source: GCVE Database
Vendor/Project: SUSE Product Security Team
Product: SUSE

Description

This security update addresses multiple vulnerabilities in libsolv, libzypp, and zypper components used by SUSE. The fixed issues include heap and stack-based buffer overflows, path traversal vulnerabilities, and arbitrary local file overwrite risks caused by crafted repository metadata or malformed files. The update also improves robustness against malformed repository data and enforces restrictions on repository path entries to prevent directory traversal outside allowed locations. These fixes mitigate potential crashes, memory corruption, and unauthorized file modifications.

Affected software

suse/libzypp
pkg:rpm/suse/libzypp
Affected versions
<17.38.13
suse/libsolv
pkg:rpm/suse/libsolv
Affected versions
<0.7.39

Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 06/24/2026, 17:22:21 UTC

Technical Analysis

The update for libsolv, libzypp, and zypper resolves seven distinct vulnerabilities: CVE-2026-9149 (heap buffer overflow via negative maxsize in .solv files), CVE-2026-9150 (stack buffer overflow in Debian metadata parser handling SHA384/SHA512 checksums), CVE-2026-25707 (arbitrary local file overwrite via crafted repo metadata), CVE-2026-44933 (prevention of script escape from signature verification directory), CVE-2026-44941 and CVE-2026-44942 (path traversal via 'keyhint' and .repo file path entries), and CVE-2026-48863 (buffer overflow parsing EdDSA signatures). The libzypp component was updated to version 17.38.13 with enhanced validation to disallow repo paths outside the base URL and discard metadata entries that would reference locations outside the local cache. libsolv was updated to version 0.7.39 with improved robustness against corrupt files and added limit checks to prevent overflows. These changes collectively improve security by preventing memory corruption, unauthorized file writes, and path traversal attacks in repository handling.

Potential Impact

Exploitation of these vulnerabilities could lead to memory corruption (heap and stack buffer overflows), application crashes, and unauthorized overwriting of local files. Path traversal issues could allow attackers to access or modify files outside intended directories. These vulnerabilities affect the integrity and stability of package management operations, potentially enabling local attackers to compromise system security or disrupt package management processes.

Mitigation Recommendations

An official security update is available that addresses all listed vulnerabilities. Users should apply the update to libsolv, libzypp, and zypper as provided by the SUSE Product Security Team. The update enforces path restrictions, sanitizes repository metadata, and fixes buffer overflow conditions. No additional mitigation steps are required beyond applying the official update.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Csaf Category
csaf_security_advisory
Csaf Version
2.0
Publisher
SUSE Product Security Team
Advisory Id
SUSE-SU-2026:2590-1
Cve Count
7
Additional Cves
["CVE-2026-44933","CVE-2026-44941","CVE-2026-44942","CVE-2026-48863","CVE-2026-9149","CVE-2026-9150"]
Cvss Version
null

Threat ID: 6a3c0d28eed863c81e23f1ca

Added to database: 06/24/2026, 17:00:24 UTC

Last enriched: 06/24/2026, 17:22:21 UTC

Last updated: 06/24/2026, 18:27:22 UTC

Views: 6

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses