Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

SUSE-SU-2026:3225-1

Опубликовано: 23 июл. 2026
Источник: suse-cvrf

Описание

Security update for apache-commons-compress, apache-ivy, brotli-java, zstd-jni

This update for apache-commons-compress, apache-ivy, brotli-java, zstd-jni fixes the following issue

Security issues fixed:

  • CVE-2026-26032: improper pathname limitation in PackagerResolver allows for arbitrary files writes outside of the configured buildRoot directory (bsc#1271727).

Other updates and bugfixes:

  • Update apache-commons-compress to 1.28.0.
  • Update apache-ivy to 2.6.0.
  • Include brotli-java and update to 1.2.0.
  • Include zstd-jni and update to v1.5.7.11.

Список пакетов

SUSE Linux Enterprise Module for Basesystem 15 SP7
apache-commons-compress-1.28.0-150200.3.19.1
SUSE Linux Enterprise Module for Development Tools 15 SP7
apache-ivy-2.6.0-150200.3.12.1

Описание

The PackagerResolver of Apache Ivy is able to download online artifacts and to (re)package them in a format defined by a packager.xml file. This repackaging is done by an Ant script, which is stored in a subdirectory of the configured "buildRoot" directory. This subdirectory is calculated based on modules coordinates, like the organisation, name or version. If one of the coordinates contains "../" sequences - which are valid characters for Ivy coordinates in general- it is possible to break out of the configured "buildRoot" directory where other files can be overwritten. In order to exploit this vulnerability an attacker needs to have access to a packager repository and add or modify the coordinates in ivy.xml files to have such "../" sequences. Users of Apache Ivy 2.0.0 to 2.5.3 (inclusive) should upgrade to Ivy 2.6.0.


Затронутые продукты
SUSE Linux Enterprise Module for Basesystem 15 SP7:apache-commons-compress-1.28.0-150200.3.19.1
SUSE Linux Enterprise Module for Development Tools 15 SP7:apache-ivy-2.6.0-150200.3.12.1

Ссылки