This update for libsolv, libzypp, zypper fixes the following issues
* CVE-2026-9149: Heap buffer overflow in libsolv repo_add_solv via negative
maxsize from crafted .solv file (bsc#1265935).
* CVE-2026-9150: Stack-based buffer overflow in libsolv's Debian metadata
parser when handling SHA384/SHA512 checksums (bsc#1265938).
* CVE-2026-25707: Handcrafted repo metadata may cause arbitrary local files to
be overwritten (bsc#1259802).
* CVE-2026-44933: scan of the Mandatory signature verification plugin support
(bsc#1265223).
* CVE-2026-44941: path traversal via "keyhint" (bsc#1267426).
* CVE-2026-44942: .repo files can have an optional path which can lead to path
traversal attacks (bsc#1267874).
* CVE-2026-48863: Fix buffer overflow when parsing EdDSA signature
(bsc#1266039).
Changes in libzypp:
Updated to version 17.38.13 (35):
* A .repo files "path=" entry must not refer to a location outside the repo
(bsc#1267874, CVE-2026-44942) A...
Read the Full Advisory## Patch Instructions:
To install this SUSE update use the SUSE recommended installation methods like
YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
* SUSE Linux Enterprise Server for SAP Applications 15 SP6
zypper in -t patch SUSE-SLE-INSTALLER-15-SP6-2026-2590=1 SUSE-SLE-Product-
SLES_SAP-15-SP6-2026-2590=1
* SUSE Linux Enterprise High Performance Computing 15 SP6
zypper in -t patch SUSE-SLE-INSTALLER-15-SP6-2026-2590=1
* SUSE Linux Enterprise Desktop 15 SP6
zypper in -t patch SUSE-SLE-INSTALLER-15-SP6-2026-2590=1
* SUSE Linux Enterprise Server 15 SP6
zypper in -t patch SUSE-SLE-INSTALLER-15-SP6-2026-2590=1
* SUSE Linux Enterprise Server 15 SP6 LTSS
zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-2590=1
* openSUSE Leap 15.6
zypper in -t patch SUSE-2026-2590=1
* SUSE Linux Enterprise Server for SAP Applications 15 SP6 (ppc64le x86_64)
* zypper-1.14.98-150600.10.55.1
* python311-solv-0.7.39-150600.8.24.1
* libsolv-tools-base-0.7.39-150600.8.24.1
* libsolv-tools-debuginfo-0.7.39-150600.8.24.1
* libzypp-devel-17.38.13-150600.3.92.1
* libsolv-tools-0.7.39-150600.8.24.1
* libzypp-17.38.13-150600.3.92.1
* libsolv-devel-debuginfo-0.7.39-150600.8.24.1
* zypper-debuginfo-1.14.98-150600.10.55.1
* ruby-solv-debuginfo-0.7.39-150600.8.24.1
* perl-solv-0.7.39-150600.8.24.1
* libsolv-debugsource-0.7.39-150600.8.24.1
* python3-solv-debuginfo-0.7.39-150600.8.24.1
* libsolv-debuginfo-0.7.39-150600.8.24.1
* zypper-debugsource-1.14.98-150600.10.55.1
* libzypp-debugsource-17.38.13-150600.3.92.1
* perl-solv-debuginfo-0.7.39-150600.8.24.1
* libzypp-debuginfo-17.38.13-150600.3.92.1
* libsolv-devel-0.7.39-150600.8.24.1
* python3-solv-0.7.39-150600.8.24.1
* ruby-solv-0.7.39-150600.8.24.1
* SUSE Linux Enterprise Server for SAP Applications 15 SP6 (noarch)
*...
Read the Full Advisory* bsc#1158038
* bsc#1239718
* bsc#1246504
* bsc#1247948
* bsc#1249435
* bsc#1252744
* bsc#1253193
* bsc#1253740
* bsc#1257068
* bsc#1257882
* bsc#1258193
* bsc#1259311
* bsc#1259706
* bsc#1259802
* bsc#1259842
* bsc#1265223
* bsc#1265935
* bsc#1265938
* bsc#1266039
* bsc#1267426
* bsc#1267874
* jsc#PED-13680
* jsc#PED-14658
* jsc#PED-15607
## References:
* https://www.suse.com/security/cve/CVE-2026-25707.html
* https://www.suse.com/security/cve/CVE-2026-44933.html
* https://www.suse.com/security/cve/CVE-2026-44941.html
* https://www.suse.com/security/cve/CVE-2026-44942.html
* https://www.suse.com/security/cve/CVE-2026-48863.html
* https://www.suse.com/security/cve/CVE-2026-9149.html
* https://www.suse.com/security/cve/CVE-2026-9150.html
* https://bugzilla.suse.com/show_bug.cgi?id=1158038
* https://bugzilla.suse.com/show_bug.cgi?id=1239718
* https://bugzilla.suse.com/show_bug.cgi?id=1246504
* https://bugzilla.suse.com/show_bug.cgi?id=1247948
* https://bugzilla.suse.com/show_bug.cgi?id=1249435
*...
Read the Full AdvisoryGet the latest Linux and open source security news straight to your inbox.