CVE-2026-25707: Handcrafted repo metadata may cause arbitrary local files to be overwritten by libzypp
Published Jun 29, 2026
·Updated
A relative path traversal bug problem when processing repository metadata in libzypp before 17.38.10 could be used by remote attackers supplying repositories to overwrite files on the system, leading to denial of service or privilege escalation.
Affected Software
2 affected components
libzypp libzypp<17.38.10
openSUSE Libzypp<17.38.10
Remediation
Event History
Jun 29, 2026
CVE Published
via MITRE·10:04 AM
Data Sourced
via MITRE·10:04 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·10:16 AM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-25707?
CVE-2026-25707 has a severity rating of high, with a score of 8.8.
2
How do I fix CVE-2026-25707?
To fix CVE-2026-25707, upgrade libzypp to version 17.38.10 or later.
3
What causes CVE-2026-25707?
CVE-2026-25707 is caused by a relative path traversal vulnerability in libzypp when processing repository metadata.
4
What are the potential impacts of CVE-2026-25707?
CVE-2026-25707 can lead to arbitrary local files being overwritten, potentially resulting in denial of service or privilege escalation.
5
Which software is affected by CVE-2026-25707?
CVE-2026-25707 affects libzypp versions prior to 17.38.10.