DEBIAN-CVE-2026-25707

Source
https://security-tracker.debian.org/tracker/CVE-2026-25707
Import Source
https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2026-25707.json
JSON Data
https://api.test.osv.dev/v1/vulns/DEBIAN-CVE-2026-25707
Upstream
Published
2026-06-29T10:16:30Z
Modified
2026-09-01T16:06:36Z
Severity
  • 8.8 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H CVSS Calculator
Summary
[none]
Details

A relative path traversal bug problem when processing repository metadata in libzypp before 17.38.10 could be used by remote attackers supplying repositories to overwrite files on the system, leading to denial of service or privilege escalation.

References

Affected packages

Debian:12 / libzypp

Package

Name
libzypp
Purl
pkg:deb/debian/libzypp?arch=source&distro=bookworm

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected

Affected versions

17.*
17.25.7-2.4
17.31.15-1
17.31.16-1
17.31.17-1
17.31.20-1
17.31.21-1
17.31.21-2
17.31.22-1
17.31.23-1
17.31.25-1
17.31.27-1
17.31.28-1
17.31.29-1
17.31.29-1.1~exp1
17.31.31-1
17.31.31-1.1~exp1
17.32.0-1~exp1
17.32.0-1
17.32.1-1
17.32.2-1
17.32.3-1
17.32.5-1
17.32.6-1
17.33.1-1~exp
17.33.1-1
17.33.3-1
17.34.0-1~exp
17.34.0-1
17.34.1-1
17.35.0-1
17.35.0-2
17.35.1-1
17.35.2-1
17.35.3-1
17.35.4-1
17.35.7-1
17.35.8-1
17.35.9-1
17.35.10-1
17.35.11-1
17.35.12-1
17.35.13-1
17.35.14-1
17.35.15-1
17.35.16-1
17.35.18-1
17.35.19-1
17.36.0-1
17.36.1-1
17.36.2-1
17.36.4-1
17.36.5-1
17.36.6-1
17.36.7-1
17.37.16-1
17.37.17-1
17.37.18-1
17.38.1-1
17.38.2-1
17.38.3-1
17.38.4-1
17.38.5-1
17.38.6-1
17.38.7-1
17.38.8-1
17.38.9-1
17.38.11-1
17.38.12-1
17.38.13-1
17.38.13-1+sparc64
17.38.14-1

Ecosystem specific

{
    "urgency":  "not yet assigned"
}

Database specific

source
"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2026-25707.json"

Debian:13 / libzypp

Package

Name
libzypp
Purl
pkg:deb/debian/libzypp?arch=source&distro=trixie

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected

Affected versions

17.*
17.36.7-1
17.37.16-1
17.37.17-1
17.37.18-1
17.38.1-1
17.38.2-1
17.38.3-1
17.38.4-1
17.38.5-1
17.38.6-1
17.38.7-1
17.38.8-1
17.38.9-1
17.38.11-1
17.38.12-1
17.38.13-1
17.38.13-1+sparc64
17.38.14-1

Ecosystem specific

{
    "urgency":  "not yet assigned"
}

Database specific

source
"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2026-25707.json"

Debian:14 / libzypp

Package

Name
libzypp
Purl
pkg:deb/debian/libzypp?arch=source&distro=forky

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
17.38.11-1

Affected versions

17.*
17.36.7-1
17.37.16-1
17.37.17-1
17.37.18-1
17.38.1-1
17.38.2-1
17.38.3-1
17.38.4-1
17.38.5-1
17.38.6-1
17.38.7-1
17.38.8-1
17.38.9-1

Ecosystem specific

{
    "urgency":  "not yet assigned"
}

Database specific

source
"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2026-25707.json"