Security Advisory

CVE-2026-44941

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2026-07-02 15:19:05
Last updated 2026-07-07 13:14:20
Assigner suse
CVSS score 8.4
State PUBLISHED

Description

A relative path traversal in the "keyhint" option in repomd.xml parsing of libzypp before 17.38.12 can be used by attackers able to supply a malicious repository to inject or overwrite files in the target system as root.