{"id":"SUSE-SU-2026:21992-1","summary":"Security update for libzypp, libsolv","details":"This update for libzypp, libsolv fixes the following issues:\n\nlibsolv was updated to 0.7.39.\n\n- fix solv_chksum_free segfault when called with a NULL pointer\n- made repo_add_solv more robust against corrupt files\n  [bsc#1265935] [CVE-2026-9149]\n- fix potential buffer overflow when verifying EdDSA signatures\n  [bsc#1266039] [CVE-2026-48863]\n- added limit checks in multiple places to catch overflows\n- reduce the size of the language id cache\n- fixed Debian canon selection\n- fixed dbpath detection in repo_rpmdb_librpm\n- reduced stack usage in repo page compression (needed for musl)\n- fixed in earlier release: [bsc#1265938] [CVE-2026-9150]\n- fix parsing of recommends in the old Mandriva synthesis format\n\nlibzypp was updated to 17.38.11:\n\n- Fix potential crash on malformed or malicious repository\n  metadata (fixes #740)\n- Repo metadata: discard entries referring to a location outside\n  the repo (bsc#1259802, CVE-2026-25707)\n  Mirroring those data locally would refer to a location outside\n  the repo's local cache directory. Those data entries are reported\n  and discarded.\n- zypp.conf: Allow [env] section to add environment variables.\n  This feature is designed to enable environment-specific settings\n  or debugging options over an extended period. See zypp.conf(5).\n","modified":"2026-06-06T18:24:18.470844369Z","published":"2026-06-02T15:56:54Z","related":["CVE-2026-25707","CVE-2026-48863","CVE-2026-9149","CVE-2026-9150"],"upstream":["CVE-2026-25707","CVE-2026-48863","CVE-2026-9149","CVE-2026-9150"],"references":[{"type":"ADVISORY","url":"https://www.suse.com/support/update/announcement/2026/suse-su-202621992-1/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1259802"},{"type":"REPORT","url":"https://bugzilla.suse.com/1265935"},{"type":"REPORT","url":"https://bugzilla.suse.com/1265938"},{"type":"REPORT","url":"https://bugzilla.suse.com/1266039"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-25707"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-48863"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-9149"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-9150"}],"schema_version":"1.7.5"}