Описание
Security update for apache-commons-compress, apache-ivy, brotli-java, zstd-jni
This update for apache-commons-compress, apache-ivy, brotli-java, zstd-jni fixes the following issue
Security issues fixed:
- CVE-2026-26032: improper pathname limitation in
PackagerResolverallows for arbitrary files writes outside of the configuredbuildRootdirectory (bsc#1271727).
Other updates and bugfixes:
- Update
apache-commons-compressto 1.28.0. - Update
apache-ivyto 2.6.0. - Include
brotli-javaand update to 1.2.0. - Include
zstd-jniand update to v1.5.7.11.
Список пакетов
SUSE Linux Enterprise Module for Basesystem 15 SP7
SUSE Linux Enterprise Module for Development Tools 15 SP7
Ссылки
- Link for SUSE-SU-2026:3225-1
- E-Mail link for SUSE-SU-2026:3225-1
- SUSE Security Ratings
- SUSE Bug 1269480
- SUSE Bug 1271727
- SUSE CVE CVE-2026-26032 page
Описание
The PackagerResolver of Apache Ivy is able to download online artifacts and to (re)package them in a format defined by a packager.xml file. This repackaging is done by an Ant script, which is stored in a subdirectory of the configured "buildRoot" directory. This subdirectory is calculated based on modules coordinates, like the organisation, name or version. If one of the coordinates contains "../" sequences - which are valid characters for Ivy coordinates in general- it is possible to break out of the configured "buildRoot" directory where other files can be overwritten. In order to exploit this vulnerability an attacker needs to have access to a packager repository and add or modify the coordinates in ivy.xml files to have such "../" sequences. Users of Apache Ivy 2.0.0 to 2.5.3 (inclusive) should upgrade to Ivy 2.6.0.
Затронутые продукты
Ссылки
- CVE-2026-26032
- SUSE Bug 1271727