Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-44942

Опубликовано: 18 июн. 2026
Источник: redhat
CVSS3: 6.5
EPSS Низкий

Описание

A path traversal in handling the "path" component of .repo files processed by libzypp before 17.38.13 in the 17.x series, or before 16.22.19 could be used by attackers to fill directories on the system outside of the zypp cache with content.

A flaw was found in libzypp. This path traversal vulnerability, present in the handling of the "path" component within .repo files, could allow attackers to write content to directories outside of the intended zypp cache. This unauthorized writing of data can lead to a Denial of Service (DoS) by filling up disk space on the system.

Отчет

This Moderate impact vulnerability in libzypp allows a path traversal when processing specially crafted .repo files. An attacker could exploit this flaw to write arbitrary content outside the intended zypp cache, potentially leading to a denial of service by exhausting disk space. This issue affects systems that process untrusted .repo files.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-22
https://bugzilla.redhat.com/show_bug.cgi?id=2490281libzypp: libzypp: Denial of Service via path traversal in .repo file handling

EPSS

Процентиль: 34%
0.00417
Низкий

6.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.5
ubuntu
около 2 месяцев назад

A path traversal in handling the "path" component of .repo files processed by libzypp before 17.38.13 in the 17.x series, or before 16.22.19 could be used by attackers to fill directories on the system outside of the zypp cache with content.

CVSS3: 6.5
nvd
около 2 месяцев назад

A path traversal in handling the "path" component of .repo files processed by libzypp before 17.38.13 in the 17.x series, or before 16.22.19 could be used by attackers to fill directories on the system outside of the zypp cache with content.

CVSS3: 6.5
debian
около 2 месяцев назад

A path traversal in handling the "path" component of .repo files proce ...

CVSS3: 6.5
github
около 2 месяцев назад

A path traversal in handling the "path" component of .repo files processed by libzypp before 17.38.13 in the 17.x series, or before 16.22.19 could be used by attackers to fill directories on the system outside of the zypp cache with content.

suse-cvrf
около 1 месяца назад

Security update for libzypp

EPSS

Процентиль: 34%
0.00417
Низкий

6.5 Medium

CVSS3