Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-25707

Опубликовано: 29 июн. 2026
Источник: redhat
CVSS3: 8.8

Описание

A relative path traversal bug problem when processing repository metadata in libzypp before 17.38.10 could be used by remote attackers supplying repositories to overwrite files on the system, leading to denial of service or privilege escalation.

A flaw was found in libzypp. A remote attacker could exploit a relative path traversal vulnerability when processing repository metadata. By supplying malicious repositories, an attacker could overwrite arbitrary files on the system. This could lead to privilege escalation or a denial of service.

Отчет

Important: A path traversal vulnerability in libzypp allows remote attackers to overwrite arbitrary files on the system by supplying malicious repository metadata. This could lead to privilege escalation or denial of service. Exploitation requires user interaction, as a user must add the untrusted repository.

Меры по смягчению последствий

Red Hat has investigated whether a possible mitigation exists for this issue, and has not been able to identify a practical example. Please update the affected package as soon as possible.

Дополнительная информация

Статус:

Important
Дефект:
CWE-22
https://bugzilla.redhat.com/show_bug.cgi?id=2494146libzypp: libzypp: Privilege escalation via relative path traversal in repository metadata processing

8.8 High

CVSS3

Связанные уязвимости

CVSS3: 8.8
ubuntu
около 2 месяцев назад

A relative path traversal bug problem when processing repository metadata in libzypp before 17.38.10 could be used by remote attackers supplying repositories to overwrite files on the system, leading to denial of service or privilege escalation.

CVSS3: 8.8
nvd
около 2 месяцев назад

A relative path traversal bug problem when processing repository metadata in libzypp before 17.38.10 could be used by remote attackers supplying repositories to overwrite files on the system, leading to denial of service or privilege escalation.

CVSS3: 8.8
debian
около 2 месяцев назад

A relative path traversal bug problem when processing repository metad ...

CVSS3: 8.8
github
около 2 месяцев назад

A relative path traversal bug problem when processing repository metadata in libzypp before 17.38.10 could be used by remote attackers supplying repositories to overwrite files on the system, leading to denial of service or privilege escalation.

suse-cvrf
около 2 месяцев назад

Security update for libzypp

8.8 High

CVSS3