Alerts This Week
Warning Icon 1 1,039
Alerts This Week
Warning Icon 1 1,039

SUSE Libzypp Moderate Path Traversal Local Overwrite Issue 2026-2628-1

suse
Calendar Grey June 25, 2026
Dist Suse Esm H88
This update fixes two security issues in libzypp, addressing local file overwrites and path traversal attacks.
An update that solves two vulnerabilities can now be installed.

Summary

## This update for libzypp fixes the following issue * CVE-2026-25707: Handcrafted repo metadata may cause arbitrary local files to be overwritten (bsc#1259802). * CVE-2026-44942: Fixed possible path traversal attacks via .repo files 'path=' entries (bsc#1267874).

References

* bsc#1259802

* bsc#1267874

Cross-

* CVE-2026-25707

* CVE-2026-44942

CVSS scores:

* CVE-2026-25707 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N

* CVE-2026-44942 ( SUSE ): 6.0

CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N

* CVE-2026-44942 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

* CVE-2026-44942 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Affected Products:

* SUSE Linux Enterprise High Performance Computing 12 SP5

* SUSE Linux Enterprise Server 12 SP5

* SUSE Linux Enterprise Server 12 SP5 LTSS

* SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security

* SUSE Linux Enterprise Server for SAP Applications 12 SP5

An update that solves two vulnerabilities can now be installed.

##

Severity
moderate
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2026:2628-1
Release Date: 2026-06-25T08:25:22Z
Rating: moderate

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here