SUSE-SU-2026:22858-1: moderate: Security update for apache-ivy

SLE-SECURITY-UPDATES null at suse.de
Mon Jul 27 17:27:31 UTC 2026


# Security update for apache-ivy

Announcement ID: SUSE-SU-2026:22858-1  
Release Date: 2026-07-22T17:49:04Z  
Rating: moderate  
References:

  * bsc#1271727

  
Cross-References:

  * CVE-2026-26032

  
CVSS scores:

  * CVE-2026-26032 ( SUSE ):  5.9
    CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
  * CVE-2026-26032 ( SUSE ):  5.3 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:H/A:N
  * CVE-2026-26032 ( NVD ):  5.4 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N

  
Affected Products:

  * SUSE Linux Enterprise Server 16.0
  * SUSE Linux Enterprise Server for SAP applications 16.0

  
  
An update that solves one vulnerability can now be installed.

## Description:

This update for apache-ivy fixes the following issue:

  * CVE-2026-26032: directory traversal sequences in module coordinates can
    allow overwriting arbitrary files outside the configured "buildRoot"
    directory (bsc#1271727).

Changes for apache-ivy:

  * Upgrade to 2.6.0:

  * the ivy:retrieve task failed when the retrieve pattern contained some text
    in parentheses before the first token, for instance: /jobs/lib (JDK
    17)/[artifact].[ext] (IVY-1660)

  * when the ivy:deliver task is configured to replace dynamic revisions, it now
    replaces these revisions to the resolved revision before any conflict
    resolution was done, which was the original behavior before Ivy 2.3.0. This
    way, the delivered ivy.xml can be used to have reproducible dependency
    resolution, especially when multiple configurations are used. It also fixes
    issues where the dynamic revisions were replaced by versions from other
    configurations. (IVY-1485, IVY-1661)
  * the ivy:deliver task didn't replace dynamic revision from inherited
    dependencies. (IVY-1410)
  * the ivy:install task didn't take the from resolver into account when
    resolving Maven parent modules or source/javadoc artifacts.
  * the ivy:checkdepsupdate task could suggest a lesser version as update.
    (IVY-1665)
  * the ivy:makepom task no longer adds a dependency to the dependencyManagement
    section. (IVY-1667)
  * the ivy:deliver task didn't include XML namespaces from a parent ivy module
    when merging the descriptors. (IVY-1658)
  * the ivy:checkdepsupdate task no longer shows evicted versions. (IVY-1662)
  * Improvements
  * use Apache Commons Compress for pack200 handling to avoid issues on Java 14
    and later. If pack200 is needed, make sure to add Apache Commons Compress to
    your classpath. (IVY-1652)
  * ivy:retrieve and the 'post resolve tasks' now support the override child
    element. (IVY-1664)
  * ivy:makepom will now add override elements of the ivy.xml to the
    dependencyManagement section of the generated pom. (IVY-1663)
  * ivy:deliver and ivy:publish now writes inherited dependencies first to
    preserve resolve order (IVY-1656)
  * ModuleRevisionId.encodeToString now returns a deterministic string that
    doesn't rely on a implmentation of HashMap
  * New feature
  * added a new nearest conflict manager, which handles conflicts in the same
    way that Maven does. (IVY-813)

## Patch Instructions:

To install this SUSE update use the SUSE recommended installation methods like
YaST online_update or "zypper patch".  
Alternatively you can run the command listed for your product:

  * SUSE Linux Enterprise Server 16.0  
    zypper in -t patch SUSE-SLES-16.0-1335=1

  * SUSE Linux Enterprise Server for SAP applications 16.0  
    zypper in -t patch SUSE-SLES-16.0-1335=1

## Package List:

  * SUSE Linux Enterprise Server 16.0 (noarch)
    * apache-ivy-2.6.0-160000.1.1
    * apache-ivy-javadoc-2.6.0-160000.1.1
  * SUSE Linux Enterprise Server for SAP applications 16.0 (noarch)
    * apache-ivy-2.6.0-160000.1.1
    * apache-ivy-javadoc-2.6.0-160000.1.1

## References:

  * https://www.suse.com/security/cve/CVE-2026-26032.html
  * https://bugzilla.suse.com/show_bug.cgi?id=1271727

-------------- next part --------------
An HTML attachment was scrubbed...
URL: <https://lists.suse.com/pipermail/sle-security-updates/attachments/20260727/375417a0/attachment.htm>


More information about the sle-security-updates mailing list