


Perceptive Security
SOC/SIEM Consultancy

A relative path traversal in the "keyhint" option in repomd.xml parsing of libzypp before 17.38.12 can be used by attackers able to supply a malicious repositor…
Published:
1 juli 2026 om 22:00:00
Alert date:
2 juli 2026 om 19:02:07
Source:
nvd.nist.gov
Operating Systems, Supply Chain & Dependencies
CVE-2026-44941 is a relative path traversal vulnerability in the libzypp package manager library affecting versions before 17.38.12. The flaw exists in the parsing of the 'keyhint' option within repomd.xml repository metadata files. An attacker who can supply a malicious repository to a target system can exploit this vulnerability to inject or overwrite arbitrary files on the system with root privileges. The vulnerability poses a high risk as it enables privilege escalation and potential full system compromise. A fix has been committed to the openSUSE/libzypp GitHub repository and tracked via SUSE Bugzilla issue 1267426. Users are advised to upgrade to libzypp version 17.38.12 or later to remediate the issue.
Technical details
Mitigation steps:
Affected products:
libzypp
openSUSE libzypp before 17.38.12
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-44941
https://bugzilla.suse.com/show_bug.cgi?id=1267426
https://github.com/openSUSE/libzypp/commit/294b1bad442d089ca671c5c03adc8031e3b29e04
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
