Executive brief
libzypp is a core library used by the Zypper package manager on SUSE and openSUSE systems to manage software repositories and updates. A vulnerability in how it handles repository metadata allows a malicious repository to trick the system into overwriting critical system files. This can lead to full system takeover (root code execution) when a user or automated process refreshes repository information, even before the user accepts any security prompts or installs any software.
Technical details
A relative path traversal vulnerability exists in the 'keyhint' option within the repomd.xml parsing logic of libzypp. The 'RepomdFileReader::keyhints()' function used a regular expression that failed to validate or sanitize path separators and '..' segments in the key filename. An attacker providing a malicious repository can use these traversal sequences to write files outside the intended metadata cache. By overwriting sensitive files like /etc/ld.so.preload, an attacker can achieve arbitrary code execution as root. This exploit can be triggered during a 'zypper refresh' operation and occurs before the user is prompted to trust the repository's signing key. The issue is fixed in libzypp version 17.38.12 by updating the regex to reject path separators in keyhints.
Affected products
- SUSE libzypp before 17.38.12
Timeline
- 2026-06-03: disclosed: Vulnerability reported by Trung Nguyen of CyStack
- 2026-06-05: patched: Fix committed to libzypp repository and submitted to OBS
- 2026-07-02: advisory: CVE-2026-44941 published