Alerts This Week
Warning Icon 1 1,220
Alerts This Week
Warning Icon 1 1,220

openSUSE libsolv Important Buffer Overflow Path Traversal Vuln 2026-2674-1

opensuse
Calendar Grey June 29, 2026
Dist Opensuse Esm H88
# Security update for libsolv, libzypp, zypper Announcement ID: SUSE-SU-2026:2674-1 Release Date: 20
An update that solves seven vulnerabilities, contains three features and has 14 security fixes can now be installed.

Description

This update for libsolv, libzypp, zypper fixes the following issues

* CVE-2026-9149: Heap buffer overflow in libsolv repo_add_solv via negative

maxsize from crafted .solv file (bsc#1265935).

* CVE-2026-9150: Stack-based buffer overflow in libsolv's Debian metadata

parser when handling SHA384/SHA512 checksums (bsc#1265938).

* CVE-2026-25707: Handcrafted repo metadata may cause arbitrary local files to

be overwritten (bsc#1259802).

* CVE-2026-44933: scan of the Mandatory signature verification plugin support

(bsc#1265223).

* CVE-2026-44941: path traversal via "keyhint" (bsc#1267426).

* CVE-2026-44942: .repo files can have an optional path which can lead to path

traversal attacks (bsc#1267874).

* CVE-2026-48863: Fix buffer overflow when parsing EdDSA signature

(bsc#1266039).

Changes in libzypp:

Updated to version 17.38.13 (35):

* A .repo files "path=" entry must not refer to a location outside the repo

(bsc#1267874, CVE-2026-44942) A...

Read the Full Advisory

Patch

## Patch Instructions:

To install this SUSE update use the SUSE recommended installation methods like

YaST online_update or "zypper patch".

Alternatively you can run the command listed for your product:

* SUSE Manager Server 4.3

zypper in -t patch SUSE-SLE-INSTALLER-15-SP4-2026-2674=1

* SUSE Linux Enterprise Server 15 SP4

zypper in -t patch SUSE-SLE-INSTALLER-15-SP4-2026-2674=1

* SUSE Linux Enterprise High Performance Computing 15 SP4

zypper in -t patch SUSE-SLE-INSTALLER-15-SP4-2026-2674=1

* SUSE Linux Enterprise Micro for Rancher 5.4

zypper in -t patch SUSE-SLE-Micro-5.4-2026-2674=1

* SUSE Linux Enterprise Micro 5.4

zypper in -t patch SUSE-SLE-Micro-5.4-2026-2674=1

* SUSE Linux Enterprise Micro for Rancher 5.3

zypper in -t patch SUSE-SLE-Micro-5.3-2026-2674=1

* SUSE Linux Enterprise Micro 5.3

zypper in -t patch SUSE-SLE-Micro-5.3-2026-2674=1

* SUSE Linux Enterprise Server for SAP Applications 15 SP4

zypper in -t patch SUSE-SLE-INSTALLER-15-SP4-2026-2674=1 SUSE-SLE-Product-

SLES_SAP-15-SP4-2026-2674=1

*...

Read the Full Advisory

Package List

* SUSE Manager Server 4.3 (ppc64le s390x x86_64)

* libsolv-tools-base-0.7.39-150400.3.46.1

* libsolv-tools-0.7.39-150400.3.46.1

* libzypp-17.38.13-150400.3.158.1

* SUSE Manager Server 4.3 (ppc64le)

* libsolv-tools-base-debuginfo-0.7.39-150400.3.46.1

* SUSE Linux Enterprise Server for SAP Applications 15 SP4 (ppc64le x86_64)

* libsolv-devel-debuginfo-0.7.39-150400.3.46.1

* perl-solv-0.7.39-150400.3.46.1

* libsolv-debugsource-0.7.39-150400.3.46.1

* libzypp-devel-17.38.13-150400.3.158.1

* libsolv-tools-0.7.39-150400.3.46.1

* libsolv-tools-base-debuginfo-0.7.39-150400.3.46.1

* libzypp-17.38.13-150400.3.158.1

* libsolv-debuginfo-0.7.39-150400.3.46.1

* libsolv-tools-debuginfo-0.7.39-150400.3.46.1

* libsolv-tools-base-0.7.39-150400.3.46.1

* perl-solv-debuginfo-0.7.39-150400.3.46.1

* ruby-solv-0.7.39-150400.3.46.1

* libzypp-debugsource-17.38.13-150400.3.158.1

* python3-solv-debuginfo-0.7.39-150400.3.46.1

* python3-solv-0.7.39-150400.3.46.1

* zypper-debugsource-1.14.98-150400.3.104.1

*...

Read the Full Advisory

References

* bsc#1158038

* bsc#1239718

* bsc#1246504

* bsc#1247948

* bsc#1249435

* bsc#1252744

* bsc#1253193

* bsc#1253740

* bsc#1257068

* bsc#1257882

* bsc#1258193

* bsc#1259311

* bsc#1259706

* bsc#1259802

* bsc#1259842

* bsc#1265223

* bsc#1265935

* bsc#1265938

* bsc#1266039

* bsc#1267426

* bsc#1267874

* jsc#PED-13680

* jsc#PED-14658

* jsc#PED-15607

## References:

* https://www.suse.com/security/cve/CVE-2026-25707.html

* https://www.suse.com/security/cve/CVE-2026-44933.html

* https://www.suse.com/security/cve/CVE-2026-44941.html

* https://www.suse.com/security/cve/CVE-2026-44942.html

* https://www.suse.com/security/cve/CVE-2026-48863.html

* https://www.suse.com/security/cve/CVE-2026-9149.html

* https://www.suse.com/security/cve/CVE-2026-9150.html

* https://bugzilla.suse.com/show_bug.cgi?id=1158038

* https://bugzilla.suse.com/show_bug.cgi?id=1239718

* https://bugzilla.suse.com/show_bug.cgi?id=1246504

* https://bugzilla.suse.com/show_bug.cgi?id=1247948

* https://bugzilla.suse.com/show_bug.cgi?id=1249435

*...

Read the Full Advisory

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2026:2674-1
Release Date: 2026-06-29T09:41:17Z
Affected Products: * openSUSE Leap 15.4 * SUSE Linux Enterprise Desktop 15 SP4 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 * SUSE Linux Enterprise Micro 5.3 * SUSE Linux Enterprise Micro 5.4 * SUSE Linux Enterprise Micro for Rancher 5.3 * SUSE Linux Enterprise Micro for Rancher 5.4 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP4 LTSS * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Manager Proxy 4.3 * SUSE Manager Retail Branch Server 4.3 * SUSE Manager Server 4.3

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here