Ghostwire

CVE-2026-44941: A relative path traversal in the "keyhint" option in repomd.xml parsing of libzypp before 17.38.12 can be used by...

HIGH CVSS 0.0

Published: July 2, 2026 | Last Modified: July 2, 2026

Description

A relative path traversal in the "keyhint" option in repomd.xml parsing of libzypp before 17.38.12 can be used by attackers able to supply a malicious repository to inject or overwrite files in the target system as root.

Ghostwire Analysis — What This Means Practically

This analysis is generated by Ghostwire from NVD, CISA KEV, EPSS, and open-source intelligence data. Verify findings through primary sources before acting.

Security Coverage (1 articles)

References