SUSE-SU-2026:21992-1

Source
https://www.suse.com/support/update/announcement/2026/suse-su-202621992-1/
Import Source
https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:21992-1.json
JSON Data
https://api.test.osv.dev/v1/vulns/SUSE-SU-2026:21992-1
Upstream
CVE (4)
Related
Published
2026-06-02T15:56:54Z
Modified
2026-06-06T18:24:18Z
Summary
Security update for libzypp, libsolv
Details

This update for libzypp, libsolv fixes the following issues:

libsolv was updated to 0.7.39.

  • fix solv_chksum_free segfault when called with a NULL pointer
  • made repo_add_solv more robust against corrupt files [bsc#1265935] [CVE-2026-9149]
  • fix potential buffer overflow when verifying EdDSA signatures [bsc#1266039] [CVE-2026-48863]
  • added limit checks in multiple places to catch overflows
  • reduce the size of the language id cache
  • fixed Debian canon selection
  • fixed dbpath detection in repo_rpmdb_librpm
  • reduced stack usage in repo page compression (needed for musl)
  • fixed in earlier release: [bsc#1265938] [CVE-2026-9150]
  • fix parsing of recommends in the old Mandriva synthesis format

libzypp was updated to 17.38.11:

  • Fix potential crash on malformed or malicious repository metadata (fixes #740)
  • Repo metadata: discard entries referring to a location outside the repo (bsc#1259802, CVE-2026-25707) Mirroring those data locally would refer to a location outside the repo's local cache directory. Those data entries are reported and discarded.
  • zypp.conf: Allow [env] section to add environment variables. This feature is designed to enable environment-specific settings or debugging options over an extended period. See zypp.conf(5).
References

Affected packages