| Name | CVE-2026-44942 |
| Description | A path traversal in handling the "path" component of .repo files processed by libzypp before 17.38.13 in the 17.x series, or before 16.22.19 could be used by attackers to fill directories on the system outside of the zypp cache with content. |
| Source | CVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more) |
Vulnerable and fixed packages
The table below lists information on source packages.
| Source Package | Release | Version | Status |
|---|
| libzypp (PTS) | bullseye | 17.25.7-1 | vulnerable |
| bookworm | 17.25.7-2.4 | vulnerable |
| trixie | 17.36.7-1 | vulnerable |
| forky, sid | 17.38.14-1 | fixed |
The information below is based on the following data on fixed versions.
| Package | Type | Release | Fixed Version | Urgency | Origin | Debian Bugs |
|---|
| libzypp | source | (unstable) | 17.38.13-1 | | | |
Notes
[trixie] - libzypp <no-dsa> (Minor issue)
[bookworm] - libzypp <postponed> (Minor issue; requires attacker-controlled repo; unsanitized .repo path= handling present in 17.25.7)
[bullseye] - libzypp <postponed> (Minor issue; requires attacker-controlled repo; unsanitized .repo path= handling present in 17.25.7)
https://bugzilla.suse.com/show_bug.cgi?id=1267874