SUSE-SU-2026:4129-1

Source
https://www.suse.com/support/update/announcement/2026/suse-su-20264129-1/
Import Source
https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:4129-1.json
JSON Data
https://api.osv.dev/v1/vulns/SUSE-SU-2026:4129-1
Published
2026-09-11T06:52:57Z
Modified
2026-09-15T18:23:11Z
Summary
Security update for libzypp, zypper
Details

This update for libzypp, zypper fixes the following issues:

Security issue fixed:

  • invalidating legacy libzypp unsigned-repository cache state [LIBZYPP-LEGACY-CACHE-01] (bsc#1274625).
  • hasCredentials() requires both username AND password to be non-empty (bsc#1273242).
  • GPG Key hints in repoindex.xml require at least a long id to allow auto-import (bsc#1271730).

Non security issues fixed:

  • Econf parser adds tags in drop-in files outside any section to [main] (bsc#1272534).
  • libzypp: X-ZYpp-AnonymousId header anomaly (bsc#1268321).
  • Need zypper option to disable services to fix Dockerfile builds in OBS (bsc#1257249).
  • zypper loads repository data and installed packages prior to checking for required arguments (bsc#1274091).
  • Zypper patch doesn't give enough details about conflicts (bsc#1277790).
  • dependency issue for package 'python3-vsts-cd-manager' after starting the upgrade (bsc#1261038).

Changes for libzypp:

  • Update to version 17.38.15:

    • Prevent libgpgme from launching gpg-agents; we don't need them.
    • defaultLoadSystem: Hand out the ZYpp::Ptr as return value.
    • Replace popen cat/zcat with solv_xfopen for testcase loaders (fixes #749)
    • zypp: Improve Testcase Loading for MCP Tools.
    • spec: Remove useless %bcond visibility_hidden (is always ON in cmake)
    • zypp.conf: add solver.NoUpdateProvide (default: false) option.

Changes for zypper:

  • Update to version 1.14.101.
References

Affected packages

SUSE:Linux Enterprise High Performance Computing 15 SP5-ESPOS
libzypp

Package

Name
libzypp
Purl
pkg:rpm/suse/libzypp&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP5-ESPOS

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
17.38.15-150500.6.77.1

Ecosystem specific

{
    "binaries": [
        {
            "libzypp": "17.38.15-150500.6.77.1",
            "libzypp-devel": "17.38.15-150500.6.77.1",
            "zypper": "1.14.101-150500.6.48.1",
            "zypper-log": "1.14.101-150500.6.48.1",
            "zypper-needs-restarting": "1.14.101-150500.6.48.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:4129-1.json"
zypper

Package

Name
zypper
Purl
pkg:rpm/suse/zypper&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP5-ESPOS

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
1.14.101-150500.6.48.1

Ecosystem specific

{
    "binaries": [
        {
            "libzypp": "17.38.15-150500.6.77.1",
            "libzypp-devel": "17.38.15-150500.6.77.1",
            "zypper": "1.14.101-150500.6.48.1",
            "zypper-log": "1.14.101-150500.6.48.1",
            "zypper-needs-restarting": "1.14.101-150500.6.48.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:4129-1.json"
SUSE:Linux Enterprise High Performance Computing 15 SP5-LTSS
libzypp

Package

Name
libzypp
Purl
pkg:rpm/suse/libzypp&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP5-LTSS

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
17.38.15-150500.6.77.1

Ecosystem specific

{
    "binaries": [
        {
            "libzypp": "17.38.15-150500.6.77.1",
            "libzypp-devel": "17.38.15-150500.6.77.1",
            "zypper": "1.14.101-150500.6.48.1",
            "zypper-log": "1.14.101-150500.6.48.1",
            "zypper-needs-restarting": "1.14.101-150500.6.48.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:4129-1.json"
zypper

Package

Name
zypper
Purl
pkg:rpm/suse/zypper&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP5-LTSS

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
1.14.101-150500.6.48.1

Ecosystem specific

{
    "binaries": [
        {
            "libzypp": "17.38.15-150500.6.77.1",
            "libzypp-devel": "17.38.15-150500.6.77.1",
            "zypper": "1.14.101-150500.6.48.1",
            "zypper-log": "1.14.101-150500.6.48.1",
            "zypper-needs-restarting": "1.14.101-150500.6.48.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:4129-1.json"
SUSE:Linux Enterprise Installer Updates 15 SP5
libzypp

Package

Name
libzypp
Purl
pkg:rpm/suse/libzypp&distro=SUSE%20Linux%20Enterprise%20Installer%20Updates%2015%20SP5

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
17.38.15-150500.6.77.1

Ecosystem specific

{
    "binaries": [
        {
            "libzypp": "17.38.15-150500.6.77.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:4129-1.json"
SUSE:Linux Enterprise Micro 5.5
libzypp

Package

Name
libzypp
Purl
pkg:rpm/suse/libzypp&distro=SUSE%20Linux%20Enterprise%20Micro%205.5

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
17.38.15-150500.6.77.1

Ecosystem specific

{
    "binaries": [
        {
            "libzypp": "17.38.15-150500.6.77.1",
            "zypper": "1.14.101-150500.6.48.1",
            "zypper-needs-restarting": "1.14.101-150500.6.48.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:4129-1.json"
zypper

Package

Name
zypper
Purl
pkg:rpm/suse/zypper&distro=SUSE%20Linux%20Enterprise%20Micro%205.5

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
1.14.101-150500.6.48.1

Ecosystem specific

{
    "binaries": [
        {
            "libzypp": "17.38.15-150500.6.77.1",
            "zypper": "1.14.101-150500.6.48.1",
            "zypper-needs-restarting": "1.14.101-150500.6.48.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:4129-1.json"
SUSE:Linux Enterprise Server 15 SP5-LTSS
libzypp

Package

Name
libzypp
Purl
pkg:rpm/suse/libzypp&distro=SUSE%20Linux%20Enterprise%20Server%2015%20SP5-LTSS

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
17.38.15-150500.6.77.1

Ecosystem specific

{
    "binaries": [
        {
            "libzypp": "17.38.15-150500.6.77.1",
            "libzypp-devel": "17.38.15-150500.6.77.1",
            "zypper": "1.14.101-150500.6.48.1",
            "zypper-log": "1.14.101-150500.6.48.1",
            "zypper-needs-restarting": "1.14.101-150500.6.48.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:4129-1.json"
zypper

Package

Name
zypper
Purl
pkg:rpm/suse/zypper&distro=SUSE%20Linux%20Enterprise%20Server%2015%20SP5-LTSS

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
1.14.101-150500.6.48.1

Ecosystem specific

{
    "binaries": [
        {
            "libzypp": "17.38.15-150500.6.77.1",
            "libzypp-devel": "17.38.15-150500.6.77.1",
            "zypper": "1.14.101-150500.6.48.1",
            "zypper-log": "1.14.101-150500.6.48.1",
            "zypper-needs-restarting": "1.14.101-150500.6.48.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:4129-1.json"
SUSE:Linux Enterprise Server for SAP Applications 15 SP5
libzypp

Package

Name
libzypp
Purl
pkg:rpm/suse/libzypp&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2015%20SP5

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
17.38.15-150500.6.77.1

Ecosystem specific

{
    "binaries": [
        {
            "libzypp": "17.38.15-150500.6.77.1",
            "libzypp-devel": "17.38.15-150500.6.77.1",
            "zypper": "1.14.101-150500.6.48.1",
            "zypper-log": "1.14.101-150500.6.48.1",
            "zypper-needs-restarting": "1.14.101-150500.6.48.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:4129-1.json"
zypper

Package

Name
zypper
Purl
pkg:rpm/suse/zypper&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2015%20SP5

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
1.14.101-150500.6.48.1

Ecosystem specific

{
    "binaries": [
        {
            "libzypp": "17.38.15-150500.6.77.1",
            "libzypp-devel": "17.38.15-150500.6.77.1",
            "zypper": "1.14.101-150500.6.48.1",
            "zypper-log": "1.14.101-150500.6.48.1",
            "zypper-needs-restarting": "1.14.101-150500.6.48.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:4129-1.json"