SUSE-SU-2026:4092-1
Dashboard / Vulnerabilities / SUSE-SU-2026:4092-1
SUSE-SU-2026:4092-1
Summary: Security update for libzypp, zypper
Details: This update for libzypp, zypper fixes the following issues: Security issue fixed: - invalidating legacy libzypp unsigned-repository cache state [LIBZYPP-LEGACY-CACHE-01] (bsc#1274625). - hasCredentials() requires both username AND password to be non-empty (bsc#1273242). - GPG Key hints in repoindex.xml require at least a long id to allow auto-import (bsc#1271730). Non security issues fixed: - Econf parser adds tags in drop-in files outside any section to [main] (bsc#1272534). - libzypp: X-ZYpp-AnonymousId header anomaly (bsc#1268321). - Need zypper option to disable services to fix Dockerfile builds in OBS (bsc#1257249). - zypper loads repository data and installed packages prior to checking for required arguments (bsc#1274091). - Zypper patch doesn't give enough details about conflicts (bsc#1277790). - dependency issue for package 'python3-vsts-cd-manager' after starting the upgrade (bsc#1261038). Changes for libzypp: - Update to version 17.38.15: - Prevent libgpgme from launching gpg-agents; we don't need them. - defaultLoadSystem: Hand out the ZYpp::Ptr as return value. - Replace popen cat/zcat with solv_xfopen for testcase loaders (fixes #749) - zypp: Improve Testcase Loading for MCP Tools. - spec: Remove useless %bcond visibility_hidden (is always ON in cmake) - zypp.conf: add solver.NoUpdateProvide (default: false) option. Changes for zypper: - Update to version 1.14.101.
References: https://www.suse.com/support/update/announcement/2026/suse-su-20264092-1/, https://bugzilla.suse.com/1257249, https://bugzilla.suse.com/1261038, https://bugzilla.suse.com/1268321, https://bugzilla.suse.com/1271730, https://bugzilla.suse.com/1272534, https://bugzilla.suse.com/1273242, https://bugzilla.suse.com/1274091, https://bugzilla.suse.com/1274625, https://bugzilla.suse.com/1277790
Affected packages
Package
Name: libzypp
Purl: pkg:rpm/suse/libzypp&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Basesystem%2015%20SP7
Affected ranges
Type: ECOSYSTEM
Events:
