{"id":"SUSE-SU-2026:4092-1","summary":"Security update for libzypp, zypper","details":"This update for libzypp, zypper fixes the following issues:\n\nSecurity issue fixed:\n\n- invalidating legacy libzypp unsigned-repository cache state [LIBZYPP-LEGACY-CACHE-01] (bsc#1274625).\n- hasCredentials() requires both username AND password to be non-empty (bsc#1273242).\n- GPG Key hints in repoindex.xml require at least a long id to allow auto-import (bsc#1271730).\n\nNon security issues fixed:\n\n- Econf parser adds tags in drop-in files outside any section to [main] (bsc#1272534).\n- libzypp: X-ZYpp-AnonymousId header anomaly (bsc#1268321).\n- Need zypper option to disable services to fix Dockerfile builds in OBS (bsc#1257249).\n- zypper loads repository data and installed packages prior to checking for required arguments (bsc#1274091).\n- Zypper patch doesn't give enough details about conflicts (bsc#1277790).\n- dependency issue for package 'python3-vsts-cd-manager' after starting the upgrade (bsc#1261038).\n\nChanges for libzypp:\n\n- Update to version 17.38.15:\n\n  - Prevent libgpgme from launching gpg-agents; we don't need them.\n  - defaultLoadSystem: Hand out the ZYpp::Ptr as return value.\n  - Replace popen cat/zcat with solv_xfopen for testcase loaders\n    (fixes #749)\n  - zypp: Improve Testcase Loading for MCP Tools.\n  - spec: Remove useless %bcond visibility_hidden (is always ON in\n    cmake)\n  - zypp.conf: add solver.NoUpdateProvide (default: false) option.\n\nChanges for zypper:\n\n- Update to version 1.14.101.\n","modified":"2026-09-13T18:23:21.253219954Z","published":"2026-09-08T16:31:44Z","references":[{"type":"ADVISORY","url":"https://www.suse.com/support/update/announcement/2026/suse-su-20264092-1/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1257249"},{"type":"REPORT","url":"https://bugzilla.suse.com/1261038"},{"type":"REPORT","url":"https://bugzilla.suse.com/1268321"},{"type":"REPORT","url":"https://bugzilla.suse.com/1271730"},{"type":"REPORT","url":"https://bugzilla.suse.com/1272534"},{"type":"REPORT","url":"https://bugzilla.suse.com/1273242"},{"type":"REPORT","url":"https://bugzilla.suse.com/1274091"},{"type":"REPORT","url":"https://bugzilla.suse.com/1274625"},{"type":"REPORT","url":"https://bugzilla.suse.com/1277790"}],"affected":[{"package":{"name":"libzypp","ecosystem":"SUSE:Linux Enterprise Module for Basesystem 15 SP7","purl":"pkg:rpm/suse/libzypp&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Basesystem%2015%20SP7"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"17.38.15-150700.6.16.1"}]}],"ecosystem_specific":{"binaries":[{"zypper":"1.14.101-150700.13.9.1","zypper-log":"1.14.101-150700.13.9.1","zypper-needs-restarting":"1.14.101-150700.13.9.1","libzypp":"17.38.15-150700.6.16.1","libzypp-devel":"17.38.15-150700.6.16.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:4092-1.json"}},{"package":{"name":"zypper","ecosystem":"SUSE:Linux Enterprise Module for Basesystem 15 SP7","purl":"pkg:rpm/suse/zypper&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Basesystem%2015%20SP7"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.14.101-150700.13.9.1"}]}],"ecosystem_specific":{"binaries":[{"zypper-needs-restarting":"1.14.101-150700.13.9.1","libzypp":"17.38.15-150700.6.16.1","libzypp-devel":"17.38.15-150700.6.16.1","zypper":"1.14.101-150700.13.9.1","zypper-log":"1.14.101-150700.13.9.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:4092-1.json"}}],"schema_version":"1.9.0"}