SUSE-SU-2026:22221-1

Source
https://www.suse.com/support/update/announcement/2026/suse-su-202622221-1/
Import Source
https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:22221-1.json
JSON Data
https://api.test.osv.dev/v1/vulns/SUSE-SU-2026:22221-1
Upstream
CVE (7)
Related
Published
2026-06-19T07:11:35Z
Modified
2026-06-24T18:24:24Z
Summary
Security update for zypper, libzypp, libsolv
Details

This update for zypper, libzypp, libsolv fixes the following issues:

Changes in zypper:

Update to 1.14.98:

  • Transactional systems: Delegate rw-commands to transactional-wrapper if available (jsc#PED-13680, jsc#PED-15607) On a transactional system where the root filesystem is mounted read-only, zypper commands that modify the system cannot be executed directly. If the system provides a transactional-wrapper utility, zypper will automatically attempt to invoke it. The wrapper transparently executes the zypper command within a new, writable snapshot and manages the lifecycle of that snapshot based on the command's exit status. On transactional systems lacking a transactional-wrapper, users must manually invoke specialized tools -such as transactional-update- to install, update, or remove software.
  • Add --filter-version-change to zypper lu. Adds filtering by version change significance to reduce noise in update listings. Supports levels: rebuild (hides rebuild-only changes) and package (hides all release-only changes).
  • Autorefresh ris-services the way as plugin-services (bsc#1246504) It's actually wrong to treat service refreshes different depending on the service type. For the purpose of a service it makes no difference how the data about the repos to use are acquired.

Changes in libzypp:

Updated to 17.38.13:

  • A .repo files "path=" entry must not refer to a location outside the repo (bsc#1267874, CVE-2026-44942) A "path=" entry may solely denote a sub-directory of the baseurl where the metadata are located. A relative path trying to access data outside the baseurl is reported and sanitized.
  • Repo "keyhint" must denote a filename, no path (bsc#1267426, CVE-2026-44941)
  • Fix potential crash on malformed or malicious repository metadata (fixes #740)
  • Repo metadata: discard entries referring to a location outside the repo (bsc#1259802, CVE-2026-25707) Mirroring those data locally would refer to a location outside the repo's local cache directory. Those data entries are reported and discarded.
  • zypp.conf: Allow [env] section to add environment variables. This feature is designed to enable environment-specific settings or debugging options over an extended period. See zypp.conf(5).
  • Prevent configured scripts from escaping the sigcheck directory (bsc#1265223, CVE-2026-44933)
  • StringV: guard hasPrefix/hasPrefixCI against reading past the view end (fixes #735)
  • Mandatory signature verification plugin support (PED#11922)
  • Fix purge-kernel -rc kernel handling (bsc#1239718)
  • Explicitly_set_pool_DISTTYPE_RPM (fixes #726)
  • Check for trusted key updates when updating the general keyring (bsc#1259706)
  • Support multiple MirroredOrigin authorities (bsc#1253193)
  • Workaround doxygen bug: doxygen/doxygen#12057
  • libzypp.spec: Add missing graphviz-gd BuildRequires (boo#1259842)

Changes in libsolv:

Updated to 0.7.39:

  • fix solv_chksum_free segfault when called with a NULL pointer
  • made repo_add_solv more robust against corrupt files [bsc#1265935] [CVE-2026-9149]
  • fix potential buffer overflow when verifying EdDSA signatures [bsc#1266039] [CVE-2026-48863]
  • added limit checks in multiple places to catch overflows
  • reduce the size of the language id cache
  • fixed Debian canon selection
  • fixed dbpath detection in repo_rpmdb_librpm
  • reduced stack usage in repo page compression (needed for musl)
  • fix parsing of sha512 checksums in debian repositories [bsc#1265938] [CVE-2026-9150]
  • improve speed of dirpool_add_dir makeing parsing of filelists.xml twice as fast
  • fix parsing of recommends in the old Mandriva synthesis format
References

Affected packages

SUSE:Linux Micro 6.2 / libsolv

Package

Name
libsolv
Purl
pkg:rpm/suse/libsolv&distro=SUSE%20Linux%20Micro%206.2

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
0.7.39-160000.1.1

Ecosystem specific

{
    "binaries":  [
        {
            "libsolv-tools-base":  "0.7.39-160000.1.1",
            "libzypp":  "17.38.13-160000.1.1",
            "zypper":  "1.14.98-160000.1.1",
            "zypper-needs-restarting":  "1.14.98-160000.1.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:22221-1.json"

SUSE:Linux Micro 6.2 / libzypp

Package

Name
libzypp
Purl
pkg:rpm/suse/libzypp&distro=SUSE%20Linux%20Micro%206.2

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
17.38.13-160000.1.1

Ecosystem specific

{
    "binaries":  [
        {
            "libsolv-tools-base":  "0.7.39-160000.1.1",
            "libzypp":  "17.38.13-160000.1.1",
            "zypper":  "1.14.98-160000.1.1",
            "zypper-needs-restarting":  "1.14.98-160000.1.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:22221-1.json"

SUSE:Linux Micro 6.2 / zypper

Package

Name
zypper
Purl
pkg:rpm/suse/zypper&distro=SUSE%20Linux%20Micro%206.2

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
1.14.98-160000.1.1

Ecosystem specific

{
    "binaries":  [
        {
            "libsolv-tools-base":  "0.7.39-160000.1.1",
            "libzypp":  "17.38.13-160000.1.1",
            "zypper":  "1.14.98-160000.1.1",
            "zypper-needs-restarting":  "1.14.98-160000.1.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:22221-1.json"