Количество 9
Количество 9
CVE-2026-44933
`PluginScript` attempts to `chroot` the plugin to the `repoManagerRoot`, this root is frequently `/` (the system root) in standard configurations or when using `--root`. If the chroot target is `/`, it is a no-op, allowing the traversed path to execute host binaries (like `/bin/bash`) with root privileges.
CVE-2026-44933
`PluginScript` attempts to `chroot` the plugin to the `repoManagerRoot`, this root is frequently `/` (the system root) in standard configurations or when using `--root`. If the chroot target is `/`, it is a no-op, allowing the traversed path to execute host binaries (like `/bin/bash`) with root privileges.
CVE-2026-44933
`PluginScript` attempts to `chroot` the plugin to the `repoManagerRoot ...
GHSA-w74x-gjhj-gxwp
`PluginScript` attempts to `chroot` the plugin to the `repoManagerRoot`, this root is frequently `/` (the system root) in standard configurations or when using `--root`. If the chroot target is `/`, it is a no-op, allowing the traversed path to execute host binaries (like `/bin/bash`) with root privileges.
openSUSE-SU-2026:21096-1
Security update for zypper, libzypp, libsolv
SUSE-SU-2026:2674-1
Security update for libsolv, libzypp, zypper
SUSE-SU-2026:2590-1
Security update for libsolv, libzypp, zypper
SUSE-SU-2026:2575-1
Security update for libsolv, libzypp, zypper
SUSE-SU-2026:2531-1
Security update for libsolv, libzypp, zypper
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2026-44933 `PluginScript` attempts to `chroot` the plugin to the `repoManagerRoot`, this root is frequently `/` (the system root) in standard configurations or when using `--root`. If the chroot target is `/`, it is a no-op, allowing the traversed path to execute host binaries (like `/bin/bash`) with root privileges. | CVSS3: 7.8 | 0% Низкий | 3 месяца назад | |
CVE-2026-44933 `PluginScript` attempts to `chroot` the plugin to the `repoManagerRoot`, this root is frequently `/` (the system root) in standard configurations or when using `--root`. If the chroot target is `/`, it is a no-op, allowing the traversed path to execute host binaries (like `/bin/bash`) with root privileges. | CVSS3: 7.8 | 0% Низкий | 3 месяца назад | |
CVE-2026-44933 `PluginScript` attempts to `chroot` the plugin to the `repoManagerRoot ... | CVSS3: 7.8 | 0% Низкий | 3 месяца назад | |
GHSA-w74x-gjhj-gxwp `PluginScript` attempts to `chroot` the plugin to the `repoManagerRoot`, this root is frequently `/` (the system root) in standard configurations or when using `--root`. If the chroot target is `/`, it is a no-op, allowing the traversed path to execute host binaries (like `/bin/bash`) with root privileges. | CVSS3: 7.8 | 0% Низкий | 3 месяца назад | |
openSUSE-SU-2026:21096-1 Security update for zypper, libzypp, libsolv | около 2 месяцев назад | |||
SUSE-SU-2026:2674-1 Security update for libsolv, libzypp, zypper | около 2 месяцев назад | |||
SUSE-SU-2026:2590-1 Security update for libsolv, libzypp, zypper | около 2 месяцев назад | |||
SUSE-SU-2026:2575-1 Security update for libsolv, libzypp, zypper | около 2 месяцев назад | |||
SUSE-SU-2026:2531-1 Security update for libsolv, libzypp, zypper | около 2 месяцев назад |
Уязвимостей на страницу