Alerts This Week
Warning Icon 1 664
Alerts This Week
Warning Icon 1 664

SUSE Linux Micro 6.1 Security Update for libzypp libsolv Key 2026-21992-1

suse
Calendar Grey June 5, 2026
Dist Suse Esm H88
Install important security fix for SUSE libzypp and libsolv to resolve four vulnerabilities effectively.
An update that solves four vulnerabilities can now be installed.

Summary

## This update for libzypp, libsolv fixes the following issues: libsolv was updated to 0.7.39. * fix solv_chksum_free segfault when called with a NULL pointer * made repo_add_solv more robust against corrupt files [bsc#1265935] [CVE-2026-9149] * fix potential buffer overflow when verifying EdDSA signatures [bsc#1266039] [CVE-2026-48863] * added limit checks in multiple places to catch overflows * reduce the size of the language id cache * fixed Debian canon selection * fixed dbpath detection in repo_rpmdb_librpm * reduced stack usage in repo page compression (needed for musl) * fixed in earlier release: [bsc#1265938] [CVE-2026-9150] * fix parsing of recommends in the old Mandriva synthesis format libzypp was updated to 17.38.11: * Fix potential crash on malformed or malicious repository metadata (fixes #740)

References

* bsc#1259802

* bsc#1265935

* bsc#1265938

* bsc#1266039

Cross-

* CVE-2026-25707

* CVE-2026-48863

* CVE-2026-9149

* CVE-2026-9150

CVSS scores:

* CVE-2026-25707 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N

* CVE-2026-48863 ( SUSE ): 8.7

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N

* CVE-2026-48863 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

* CVE-2026-9149 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

* CVE-2026-9149 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

* CVE-2026-9149 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

* CVE-2026-9150 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

* CVE-2026-9150 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2026:21992-1
Release Date: 2026-06-02T16:20:17Z
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here