HIGH🇵🇱 Wersja polska

CVE-2026-44941

CVSS 8.4v3.1pub. 2026-07-02upd. 2026-07-07

A relative path traversal in the "keyhint" option in repomd.xml parsing of libzypp before 17.38.12 can be used by attackers able to supply a malicious repository to inject or overwrite files in the target system as root.

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:H
  • Opensuse Libzypp

    APP
    Opensuse
    < 17.38.12
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
Path Traversal
CWE
References

Related vulnerabilities

CVE-2026-25707HIGH8.8PL ✓same product

Path traversal w libzypp umożliwia nadpisanie plików i eskalację uprawnień

CVE-2018-7685HIGH7.8same product

The decoupled download and installation steps in libzypp before 17.5.0 could lead to a corrupted RPM being lef...

CVE-2017-7435HIGH8.1same product

In libzypp before 20170803 it was possible to add unsigned YUM repositories without warning to the user that c...

CVE-2017-7436HIGH8.1same product

In libzypp before 20170803 it was possible to retrieve unsigned packages without a warning to the user which c...

CVE-2017-9269HIGH7.7same product

In libzypp before August 2018 GPG keys attached to YUM repositories were not correctly pinned, allowing malici...