{"id":"SUSE-SU-2026:22221-1","summary":"Security update for zypper, libzypp, libsolv","details":"This update for zypper, libzypp, libsolv fixes the following issues:\n\nChanges in zypper:\n\nUpdate to 1.14.98:\n\n- Transactional systems: Delegate rw-commands to\n  transactional-wrapper if available (jsc#PED-13680, jsc#PED-15607)\n  On a transactional system where the root filesystem is mounted\n  read-only, zypper commands that modify the system cannot be\n  executed directly.\n  If the system provides a transactional-wrapper utility, zypper\n  will automatically attempt to invoke it. The wrapper\n  transparently executes the zypper command within a new, writable\n  snapshot and manages the lifecycle of that snapshot based on the\n  command's exit status.\n  On transactional systems lacking a transactional-wrapper, users\n  must manually invoke specialized tools -such as\n  transactional-update- to install, update, or remove software.\n- Add --filter-version-change to zypper lu.\n  Adds filtering by version change significance to reduce noise in\n  update listings. Supports levels: rebuild (hides rebuild-only\n  changes) and package (hides all release-only changes).\n- Autorefresh ris-services the way as plugin-services (bsc#1246504)\n  It's actually wrong to treat service refreshes different\n  depending on the service type. For the purpose of a service it\n  makes no difference how the data about the repos to use are\n  acquired.\n\nChanges in libzypp:\n\nUpdated to 17.38.13:\n\n- A .repo files \"path=\" entry must not refer to a location\n  outside the repo (bsc#1267874, CVE-2026-44942)\n  A \"path=\" entry may solely denote a sub-directory of the baseurl\n  where the metadata are located. A relative path trying to access\n  data outside the baseurl is reported and sanitized.\n- Repo \"keyhint\" must denote a filename, no path (bsc#1267426,\n  CVE-2026-44941)\n- Fix potential crash on malformed or malicious repository\n  metadata (fixes #740)\n- Repo metadata: discard entries referring to a location outside\n  the repo (bsc#1259802, CVE-2026-25707)\n  Mirroring those data locally would refer to a location outside\n  the repo's local cache directory. Those data entries are reported\n  and discarded.\n- zypp.conf: Allow [env] section to add environment variables.\n  This feature is designed to enable environment-specific settings\n  or debugging options over an extended period. See zypp.conf(5).\n- Prevent configured scripts from escaping the sigcheck directory\n  (bsc#1265223, CVE-2026-44933)\n- StringV: guard hasPrefix/hasPrefixCI against reading past the\n  view end (fixes #735)\n- Mandatory signature verification plugin support (PED#11922)\n- Fix purge-kernel -rc kernel handling (bsc#1239718)\n- Explicitly_set_pool_DISTTYPE_RPM (fixes #726)\n- Check for trusted key updates when updating the general keyring\n  (bsc#1259706)\n- Support multiple MirroredOrigin authorities (bsc#1253193)\n- Workaround doxygen bug: doxygen/doxygen#12057\n- libzypp.spec: Add missing graphviz-gd BuildRequires (boo#1259842)\n\nChanges in libsolv:\n\nUpdated to 0.7.39:\n\n- fix solv_chksum_free segfault when called with a NULL pointer\n- made repo_add_solv more robust against corrupt files\n  [bsc#1265935] [CVE-2026-9149]\n- fix potential buffer overflow when verifying EdDSA signatures\n  [bsc#1266039] [CVE-2026-48863]\n- added limit checks in multiple places to catch overflows\n- reduce the size of the language id cache\n- fixed Debian canon selection\n- fixed dbpath detection in repo_rpmdb_librpm\n- reduced stack usage in repo page compression (needed for musl)\n- fix parsing of sha512 checksums in debian repositories\n  [bsc#1265938] [CVE-2026-9150]\n- improve speed of dirpool_add_dir makeing parsing of filelists.xml\n  twice as fast\n- fix parsing of recommends in the old Mandriva synthesis format\n","modified":"2026-06-24T18:24:24.261443706Z","published":"2026-06-19T07:11:35Z","related":["CVE-2026-25707","CVE-2026-44933","CVE-2026-44941","CVE-2026-44942","CVE-2026-48863","CVE-2026-9149","CVE-2026-9150"],"upstream":["CVE-2026-25707","CVE-2026-44933","CVE-2026-44941","CVE-2026-44942","CVE-2026-48863","CVE-2026-9149","CVE-2026-9150"],"references":[{"type":"ADVISORY","url":"https://www.suse.com/support/update/announcement/2026/suse-su-202622221-1/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1239718"},{"type":"REPORT","url":"https://bugzilla.suse.com/1246504"},{"type":"REPORT","url":"https://bugzilla.suse.com/1253193"},{"type":"REPORT","url":"https://bugzilla.suse.com/1259706"},{"type":"REPORT","url":"https://bugzilla.suse.com/1259802"},{"type":"REPORT","url":"https://bugzilla.suse.com/1259842"},{"type":"REPORT","url":"https://bugzilla.suse.com/1265223"},{"type":"REPORT","url":"https://bugzilla.suse.com/1265935"},{"type":"REPORT","url":"https://bugzilla.suse.com/1265938"},{"type":"REPORT","url":"https://bugzilla.suse.com/1266039"},{"type":"REPORT","url":"https://bugzilla.suse.com/1267426"},{"type":"REPORT","url":"https://bugzilla.suse.com/1267874"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-25707"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-44933"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-44941"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-44942"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-48863"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-9149"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-9150"}],"affected":[{"package":{"name":"libsolv","ecosystem":"SUSE:Linux Micro 6.2","purl":"pkg:rpm/suse/libsolv&distro=SUSE%20Linux%20Micro%206.2"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0.7.39-160000.1.1"}]}],"ecosystem_specific":{"binaries":[{"libsolv-tools-base":"0.7.39-160000.1.1","libzypp":"17.38.13-160000.1.1","zypper":"1.14.98-160000.1.1","zypper-needs-restarting":"1.14.98-160000.1.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:22221-1.json"}},{"package":{"name":"libzypp","ecosystem":"SUSE:Linux Micro 6.2","purl":"pkg:rpm/suse/libzypp&distro=SUSE%20Linux%20Micro%206.2"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"17.38.13-160000.1.1"}]}],"ecosystem_specific":{"binaries":[{"libzypp":"17.38.13-160000.1.1","zypper":"1.14.98-160000.1.1","zypper-needs-restarting":"1.14.98-160000.1.1","libsolv-tools-base":"0.7.39-160000.1.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:22221-1.json"}},{"package":{"name":"zypper","ecosystem":"SUSE:Linux Micro 6.2","purl":"pkg:rpm/suse/zypper&distro=SUSE%20Linux%20Micro%206.2"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.14.98-160000.1.1"}]}],"ecosystem_specific":{"binaries":[{"libzypp":"17.38.13-160000.1.1","zypper":"1.14.98-160000.1.1","zypper-needs-restarting":"1.14.98-160000.1.1","libsolv-tools-base":"0.7.39-160000.1.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:22221-1.json"}}],"schema_version":"1.7.5"}