PT-2026-42136 · Libzypp · Libzypp

·

CVE-2026-44933

·

Published

2026-05-20

·

Updated

2026-06-29

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions libzypp versions prior to 17.38.9-1.1
Description The PluginScript function attempts to use chroot to restrict the plugin to the repoManagerRoot. In standard configurations or when the --root option is used, this root is often set to / (the system root). When the chroot target is /, the operation has no effect, which allows a traversed path to execute host binaries, such as /bin/bash, with root privileges.
Recommendations Update to version 17.38.9-1.1.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-44933
OPENSUSE-SU-2026:10826-1
OPENSUSE-SU-2026:21096-1
SUSE-SU-2026:22172-1
SUSE-SU-2026:22221-1
SUSE-SU-2026:2531-1
SUSE-SU-2026:2575-1
SUSE-SU-2026:2590-1
SUSE-SU-2026:2674-1

Affected Products

Libzypp