Critical Security Fix for openSUSE and SUSE libzypp zypper Vulnerabilities

Critical Security Fix for openSUSE and SUSE libzypp zypper Vulnerabilities

First seen 10 Sep 2026, 15:20 UTC Linuxsecurity 72.0

Article Content

Browse articles
ThreatCluster

On September 9, 2026, SUSE released a critical security update (SUSE-SU-2026-4112) for libzypp and zypper, addressing multiple vulnerabilities affecting various SUSE Linux distributions, including openSUSE 15.6 and SUSE Linux Enterprise 15 SP6. The vulnerabilities include issues with the legacy unsigned-repository cache state, credential handling, and GPG key hints, which could potentially allow unauthorized access or manipulation of repository data. The update fixes three critical security issues and several non-security bugs. Affected systems include SUSE Linux Enterprise Server, Desktop, and High-Performance Computing editions. Users are urged to apply the patches immediately to mitigate risks. The vulnerabilities were reported under various bug tracking IDs, including bsc#1274625 and bsc#1271730. The patches can be installed using standard SUSE installation methods such as YaST or zypper commands. The update is critical, and users should prioritize applying it to ensure system security.

Key Points: • Critical vulnerabilities in libzypp and zypper require immediate patching. • Affected systems include openSUSE 15.6 and SUSE Linux Enterprise 15 SP6. • Patches address issues with repository cache state, credential handling, and GPG key hints.

Ask AI about this cluster

Timeline

2026-09-08
SUSE releases critical update SUSE-SU-2026-4112
SUSE announced a critical update for libzypp and zypper, fixing multiple vulnerabilities affecting various distributions.
Linuxsecurity
2026-09-09
Update available for installation
Users are advised to apply the critical patches using YaST or zypper commands to secure their systems.
Linuxsecurity
2026-09-10
Linuxsecurity publishes advisory on vulnerabilities
Linuxsecurity reports on the critical vulnerabilities and the necessity for immediate patching across affected systems.
Linuxsecurity