Linuxsecurity SUSE Linux Micro libzypp Vulnerabilities Addressed in Recent Updates
Article Content
- •SUSE released updates for libzypp addressing two moderate vulnerabilities.
- •CVE-2026-44941 and CVE-2026-44942 involve path traversal attacks.
- •Affected systems include SUSE Linux Micro 6.0 and 6.1; users should update promptly.
SUSE has released updates for its libzypp package to address two moderate vulnerabilities affecting SUSE Linux Micro 6.0 and 6.1. The vulnerabilities, identified as CVE-2026-44941 and CVE-2026-44942, involve path traversal attacks that could allow unauthorized access to sensitive files. CVE-2026-44941 affects the 'keyhint' feature, while CVE-2026-44942 pertains to optional paths in .repo files. Both vulnerabilities have been rated moderate in severity, with CVSS scores ranging from 6.0 to 7.5. Users are urged to apply the updates promptly to mitigate potential exploitation risks. The updates were released on June 9, 2026, for both versions. The vulnerabilities were confirmed by SUSE's advisory reports.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (4)
Following this threat?
Track CVE-2026-44941 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical GitLab Vulnerabilities Exploited Within Hours of Disclosure On September 10, 2026, GitLab released patches for critical vulnerabilities CVE-2026-85706 and CVE-2026-87719. CVE-2026-85706, a path traversal flaw, allows unauthenticated users to read arbitrary files from GitLab servers, while CVE-2026-87719 enables credential theft via insecure deserialization. Both…
Multiple CVEs Expose Vulnerabilities in Cybersecurity Tools and Applications A series of vulnerabilities have been reported affecting various cybersecurity tools and applications. Notable among them is CVE-2024-51482, a blind SQL injection vulnerability in ZoneMinder, allowing attackers to execute arbitrary SQL commands on the database server. CVE-2026-22557, a path traversal vulnerability in…