Script 'mail_helper' called by obssrc Hello community, here is the log from the commit of package libzypp for openSUSE:Factory checked in at 2026-05-20 15:23:11 ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++ Comparing /work/SRC/openSUSE:Factory/libzypp (Old) and /work/SRC/openSUSE:Factory/.libzypp.new.1966 (New) ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
Package is "libzypp" Wed May 20 15:23:11 2026 rev:531 rq:1353995 version:17.38.9 Changes: -------- --- /work/SRC/openSUSE:Factory/libzypp/libzypp.changes 2026-05-14 21:42:03.928405604 +0200 +++ /work/SRC/openSUSE:Factory/.libzypp.new.1966/libzypp.changes 2026-05-20 15:23:35.135829392 +0200 @@ -1,0 +2,9 @@ +Tue May 19 09:21:50 CEST 2026 - [email protected] + +- Prevent configured scripts from escaping the sigcheck directory + (bsc#1265223, CVE-2026-44933) +- StringV: guard hasPrefix/hasPrefixCI against reading past the + view end (fixes #735) +- version 17.38.9 (35) + +------------------------------------------------------------------- Old: ---- libzypp-17.38.8.tar.bz2 New: ---- libzypp-17.38.9.tar.bz2 ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++ Other differences: ------------------ ++++++ libzypp.spec ++++++ --- /var/tmp/diff_new_pack.OfWwai/_old 2026-05-20 15:23:35.863859334 +0200 +++ /var/tmp/diff_new_pack.OfWwai/_new 2026-05-20 15:23:35.867859499 +0200 @@ -98,7 +98,7 @@ %endif Name: libzypp -Version: 17.38.8 +Version: 17.38.9 Release: 0 License: GPL-2.0-or-later URL: https://github.com/openSUSE/libzypp ++++++ libzypp-17.38.8.tar.bz2 -> libzypp-17.38.9.tar.bz2 ++++++ ++++ 1846 lines of diff (skipped)
