openSUSE-SU-2026:21225-1: important: Security update for rmt-server

[email protected]
Newsgroups gmane.linux.suse.security.announce
Message-ID <[email protected]>
openSUSE security update: security update for rmt-server
-------------------------------------------------------------

Announcement ID: openSUSE-SU-2026:21225-1
Rating: important
References:

  * bsc#1246976
  * bsc#1248510
  * bsc#1248869
  * bsc#1251937
  * bsc#1253146
  * bsc#1253147
  * bsc#1253953
  * bsc#1256826
  * bsc#1256883
  * bsc#1257133
  * bsc#1265369



Cross-References:

  * CVE-2026-42256



CVSS scores:

  * CVE-2026-42256 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
  * CVE-2026-42256 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N

Affected Products:

         openSUSE Leap 16.0

-------------------------------------------------------------

An update that solves one vulnerability and has 11 bug fixes can now be installed.

Description:

This update for rmt-server fixes the following issue

Update to 3.0.0:

- CVE-2026-42256: net-imap: hostile server can perform a DoS on client authenticating a connection with SCRAM-SHA1 or
  SCRAM-SHA2 (bsc#1265369).

Changes for rmt-server:

- Version 3.0.0
 * Security fix: Remove unused ActionMailer/ActionMailbox components to
 eliminate CVE-2026-42256 (bsc#1265369)
 * Split Rails meta-gem into individual components for better security control
- Version 2.26
 * Add support for processing, storing, and syncing system profiles (jsc#TEL-265)
- Version 2.25
 * fix rmt-cli list and purge commands for large data (bsc#1253146 and bsc#1253147)
 * Fix mirroring of SLE16 NVIDIA-GPU-Compute-Toolkit-CUDA repo (bsc#1256826)
 * Support for new redirect_repo_hosts config, to exclude some repo hosts
 from mirroring, and send clients directly there (jsc#SCC-452)
 * rmt-server-pubcloud
 * Clearer error message (bsc#1256883)
 * Handle zypper response when data exporter raises an error (bsc#1257133)
 * Add Valkey + Sidekiq for async processing
 * Enable mirroring xz compressed repositories (bsc#1246976)
 * Rack 2.2.20 security update (bsc#1253953, bsc#1251937)
 * Drop some de-published products from RMT
 * Include Live-Patching for SLES 15.X (jsc#PCT-630)
 * Handle only one data exporter (bsc#1248869)
 * Do not decode instance data from db to access registry (bsc#1248510)
 * Handle instance verification exceptions


Patch instructions:

   To install this openSUSE security update use the suse recommended installation methods
   like YaST online_update or "zypper patch".
   Alternatively you can run the command listed for your product:

- openSUSE Leap 16.0

   zypper in -t patch openSUSE-Leap-16.0-1154=1

Package List:

- openSUSE Leap 16.0:

  ansible-rmt-server-3.0.0-160000.1.1
  rmt-server-3.0.0-160000.1.1
  rmt-server-config-3.0.0-160000.1.1
  rmt-server-pubcloud-3.0.0-160000.1.1

References:

  * https://www.suse.com/security/cve/CVE-2026-42256.html
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.