top of page
perceptive_background_267k.jpg

A relative path traversal in the "keyhint" option in repomd.xml parsing of libzypp before 17.38.12 can be used by attackers able to supply a malicious repositor…

Published:

1 juli 2026 om 22:00:00

Alert date:

2 juli 2026 om 19:02:07

Source:

nvd.nist.gov

Click to open the original link from this advisory

Operating Systems, Supply Chain & Dependencies

CVE-2026-44941 is a relative path traversal vulnerability in the libzypp package manager library affecting versions before 17.38.12. The flaw exists in the parsing of the 'keyhint' option within repomd.xml repository metadata files. An attacker who can supply a malicious repository to a target system can exploit this vulnerability to inject or overwrite arbitrary files on the system with root privileges. The vulnerability poses a high risk as it enables privilege escalation and potential full system compromise. A fix has been committed to the openSUSE/libzypp GitHub repository and tracked via SUSE Bugzilla issue 1267426. Users are advised to upgrade to libzypp version 17.38.12 or later to remediate the issue.

Technical details

Mitigation steps:

Affected products:

libzypp
openSUSE libzypp before 17.38.12

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Deze website toont informatie afkomstig van externe bronnen; Perceptive aanvaardt geen verantwoordelijkheid voor de juistheid, volledigheid of actualiteit van deze informatie.

bottom of page