Alerts This Week
Warning Icon 1 815
Alerts This Week
Warning Icon 1 815

SUSE zypper Important Security Issues Fix Advisory 2026-22172-1

suse
Calendar Grey June 23, 2026
Dist Suse Esm H88
Critical security updates for SUSE addressing multiple vulnerabilities in zypper and libzypp to enhance system protection.
An update that solves seven vulnerabilities, contains two features and has five fixes can now be installed.

Summary

## This update for zypper, libzypp, libsolv fixes the following issues: Changes in zypper: Update to 1.14.98: * Transactional systems: Delegate rw-commands to transactional-wrapper if available (jsc#PED-13680, jsc#PED-15607) On a transactional system where the root filesystem is mounted read-only, zypper commands that modify the system cannot be executed directly. If the system provides a transactional-wrapper utility, zypper will automatically attempt to invoke it. The wrapper transparently executes the zypper command within a new, writable snapshot and manages the lifecycle of that snapshot based on the command's exit status. On transactional systems lacking a transactional-wrapper, users must manually invoke specialized tools -such as transactional-update- to install,

References

* bsc#1239718

* bsc#1246504

* bsc#1253193

* bsc#1259706

* bsc#1259802

* bsc#1259842

* bsc#1265223

* bsc#1265935

* bsc#1265938

* bsc#1266039

* bsc#1267426

* bsc#1267874

* jsc#PED-13680

* jsc#PED-15607

Cross-

* CVE-2026-25707

* CVE-2026-44933

* CVE-2026-44941

* CVE-2026-44942

* CVE-2026-48863

* CVE-2026-9149

* CVE-2026-9150

CVSS scores:

* CVE-2026-25707 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N

* CVE-2026-44933 ( SUSE ): 8.5

CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

* CVE-2026-44933 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

* CVE-2026-44933 ( NVD ): 8.5

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2026:22172-1
Release Date: 2026-06-19T07:35:00Z
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here