Описание
Security update for libzypp
This update for libzypp fixes the following issue
- CVE-2026-25707: Handcrafted repo metadata may cause arbitrary local files to be overwritten (bsc#1259802).
- CVE-2026-44942: Fixed possible path traversal attacks via .repo files 'path=' entries (bsc#1267874).
Список пакетов
Image SLES12-SP5-Azure-HPC-BYOS
libzypp-16.22.19-82.1
Image SLES12-SP5-Azure-HPC-On-Demand
libzypp-16.22.19-82.1
SUSE Linux Enterprise Server 12 SP5-LTSS
libzypp-16.22.19-82.1
libzypp-devel-16.22.19-82.1
libzypp-devel-doc-16.22.19-82.1
SUSE Linux Enterprise Server LTSS Extended Security 12 SP5
libzypp-16.22.19-82.1
libzypp-devel-16.22.19-82.1
libzypp-devel-doc-16.22.19-82.1
Ссылки
- Link for SUSE-SU-2026:2628-1
- E-Mail link for SUSE-SU-2026:2628-1
- SUSE Security Ratings
- SUSE Bug 1259802
- SUSE Bug 1267874
- SUSE CVE CVE-2026-25707 page
- SUSE CVE CVE-2026-44942 page
Описание
A relative path traversal bug problem when processing repository metadata in libzypp before 17.38.10 could be used by remote attackers supplying repositories to overwrite files on the system, leading to denial of service or privilege escalation.
Затронутые продукты
Image SLES12-SP5-Azure-HPC-BYOS:libzypp-16.22.19-82.1
Image SLES12-SP5-Azure-HPC-On-Demand:libzypp-16.22.19-82.1
SUSE Linux Enterprise Server 12 SP5-LTSS:libzypp-16.22.19-82.1
SUSE Linux Enterprise Server 12 SP5-LTSS:libzypp-devel-16.22.19-82.1
Ссылки
- CVE-2026-25707
- SUSE Bug 1259802
Описание
A path traversal in handling the "path" component of .repo files processed by libzypp before 17.38.13 in the 17.x series, or before 16.22.19 could be used by attackers to fill directories on the system outside of the zypp cache with content.
Затронутые продукты
Image SLES12-SP5-Azure-HPC-BYOS:libzypp-16.22.19-82.1
Image SLES12-SP5-Azure-HPC-On-Demand:libzypp-16.22.19-82.1
SUSE Linux Enterprise Server 12 SP5-LTSS:libzypp-16.22.19-82.1
SUSE Linux Enterprise Server 12 SP5-LTSS:libzypp-devel-16.22.19-82.1
Ссылки
- CVE-2026-44942
- SUSE Bug 1267874