High severity8.4NVD Advisory· Published Jul 2, 2026· Updated Jul 7, 2026
CVE-2026-44941
CVE-2026-44941
Description
A relative path traversal in the "keyhint" option in repomd.xml parsing of libzypp before 17.38.12 can be used by attackers able to supply a malicious repository to inject or overwrite files in the target system as root.
Affected products
6- osv-coords4 versionspkg:rpm/opensuse/libsolv&distro=openSUSE%20Leap%2016.0pkg:rpm/opensuse/libzypp&distro=openSUSE%20Leap%2016.0pkg:rpm/opensuse/libzypp&distro=openSUSE%20Tumbleweedpkg:rpm/opensuse/zypper&distro=openSUSE%20Leap%2016.0
< 0.7.39-160000.1.1+ 3 more
- (no CPE)range: < 0.7.39-160000.1.1
- (no CPE)range: < 17.38.13-160000.1.1
- (no CPE)range: < 17.38.13-1.1
- (no CPE)range: < 1.14.98-160000.1.1
Patches
Vulnerability mechanics
References
2- github.com/openSUSE/libzypp/commit/294b1bad442d089ca671c5c03adc8031e3b29e04nvdPatch
- bugzilla.suse.com/show_bug.cginvdExploitThird Party Advisory
News mentions
0No linked articles in our index yet.