SUSE-SU-2026:4092-1

Source
https://www.suse.com/support/update/announcement/2026/suse-su-20264092-1/
Import Source
https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:4092-1.json
JSON Data
https://api.osv.dev/v1/vulns/SUSE-SU-2026:4092-1
Published
2026-09-08T16:31:44Z
Modified
2026-09-13T18:23:21Z
Summary
Security update for libzypp, zypper
Details

This update for libzypp, zypper fixes the following issues:

Security issue fixed:

  • invalidating legacy libzypp unsigned-repository cache state [LIBZYPP-LEGACY-CACHE-01] (bsc#1274625).
  • hasCredentials() requires both username AND password to be non-empty (bsc#1273242).
  • GPG Key hints in repoindex.xml require at least a long id to allow auto-import (bsc#1271730).

Non security issues fixed:

  • Econf parser adds tags in drop-in files outside any section to [main] (bsc#1272534).
  • libzypp: X-ZYpp-AnonymousId header anomaly (bsc#1268321).
  • Need zypper option to disable services to fix Dockerfile builds in OBS (bsc#1257249).
  • zypper loads repository data and installed packages prior to checking for required arguments (bsc#1274091).
  • Zypper patch doesn't give enough details about conflicts (bsc#1277790).
  • dependency issue for package 'python3-vsts-cd-manager' after starting the upgrade (bsc#1261038).

Changes for libzypp:

  • Update to version 17.38.15:

    • Prevent libgpgme from launching gpg-agents; we don't need them.
    • defaultLoadSystem: Hand out the ZYpp::Ptr as return value.
    • Replace popen cat/zcat with solv_xfopen for testcase loaders (fixes #749)
    • zypp: Improve Testcase Loading for MCP Tools.
    • spec: Remove useless %bcond visibility_hidden (is always ON in cmake)
    • zypp.conf: add solver.NoUpdateProvide (default: false) option.

Changes for zypper:

  • Update to version 1.14.101.
References

Affected packages

SUSE:Linux Enterprise Module for Basesystem 15 SP7 / libzypp

Package

Name
libzypp
Purl
pkg:rpm/suse/libzypp&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Basesystem%2015%20SP7

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
17.38.15-150700.6.16.1

Ecosystem specific

{
    "binaries": [
        {
            "libzypp": "17.38.15-150700.6.16.1",
            "libzypp-devel": "17.38.15-150700.6.16.1",
            "zypper": "1.14.101-150700.13.9.1",
            "zypper-log": "1.14.101-150700.13.9.1",
            "zypper-needs-restarting": "1.14.101-150700.13.9.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:4092-1.json"

SUSE:Linux Enterprise Module for Basesystem 15 SP7 / zypper

Package

Name
zypper
Purl
pkg:rpm/suse/zypper&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Basesystem%2015%20SP7

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
1.14.101-150700.13.9.1

Ecosystem specific

{
    "binaries": [
        {
            "libzypp": "17.38.15-150700.6.16.1",
            "libzypp-devel": "17.38.15-150700.6.16.1",
            "zypper": "1.14.101-150700.13.9.1",
            "zypper-log": "1.14.101-150700.13.9.1",
            "zypper-needs-restarting": "1.14.101-150700.13.9.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:4092-1.json"