CVE-2026-44933
SUSE SUSE Linux Enterprise, openSUSE 취약점
`PluginScript` attempts to `chroot` the plugin to the `repoManagerRoot`, this root is frequently `/` (the system root) in standard configurations or when using `--root`. If the chroot target is `/`, it is a no-op, allowing the traversed path to execute host binaries (like `/bin/bash`) with root privileges.
- 대응 우선순위
- 점검
- CVSS
- 8.5
- EPSS
- 0.22% 백분위 12.6% · 2026.08.04 기준
- CISA KEV
- 미등록
- 조치 기한
- -
- 공개일
- 2026.05.20