CVE-2026-44941
EUVD-2026-4140602.07.2026, 16:16
A relative path traversal in the "keyhint" option in repomd.xml parsing of libzypp before 17.38.12 can be used by attackers able to supply a malicious repository to inject or overwrite files in the target system as root.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| opensuse | libzypp | 𝑥 < 17.38.12 |
𝑥
= Vulnerable software versions
Debian Releases
Ubuntu Releases
openSUSE / SLES Releases
openSUSE Product | |||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| libsolv-devel |
| ||||||||||||
| libsolv-tools |
| ||||||||||||
| libsolv-tools-base |
| ||||||||||||
| libzypp |
| ||||||||||||
| libzypp-devel |
| ||||||||||||
| perl-solv |
| ||||||||||||
| python3-solv |
| ||||||||||||
| python311-solv |
| ||||||||||||
| ruby-solv |
| ||||||||||||
| zypper |
| ||||||||||||
| zypper-log |
| ||||||||||||
| zypper-needs-restarting |
|