openSUSE-SU-2026:21640-1: important: Security update for rmt-server

[email protected]
Newsgroups gmane.linux.suse.security.announce
Message-ID <[email protected]>
openSUSE security update: security update for rmt-server
-------------------------------------------------------------

Announcement ID: openSUSE-SU-2026:21640-1
Rating: important
References:

  * bsc#1261388
  * bsc#1261398
  * bsc#1261406
  * bsc#1261417
  * bsc#1261426
  * bsc#1261436
  * bsc#1261447
  * bsc#1261458
  * bsc#1261466
  * bsc#1261471
  * bsc#1262706
  * bsc#1268149
  * bsc#1268301
  * bsc#1268303
  * bsc#1268305
  * bsc#1274715



Cross-References:

  * CVE-2026-26961
  * CVE-2026-26962
  * CVE-2026-34230
  * CVE-2026-34763
  * CVE-2026-34785
  * CVE-2026-34786
  * CVE-2026-34826
  * CVE-2026-34829
  * CVE-2026-34830
  * CVE-2026-34831



CVSS scores:

  * CVE-2026-26961 ( SUSE ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N
  * CVE-2026-26961 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N
  * CVE-2026-26962 ( SUSE ): 4.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N
  * CVE-2026-26962 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N
  * CVE-2026-34230 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
  * CVE-2026-34230 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
  * CVE-2026-34763 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
  * CVE-2026-34763 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
  * CVE-2026-34785 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
  * CVE-2026-34785 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
  * CVE-2026-34786 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
  * CVE-2026-34786 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N
  * CVE-2026-34826 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
  * CVE-2026-34826 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
  * CVE-2026-34829 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
  * CVE-2026-34829 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
  * CVE-2026-34830 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
  * CVE-2026-34830 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
  * CVE-2026-34831 ( SUSE ): 4.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N
  * CVE-2026-34831 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N

Affected Products:

         openSUSE Leap 16.0

-------------------------------------------------------------

An update that solves 10 vulnerabilities and has 16 bug fixes can now be installed.

Description:

This update for rmt-server fixes the following issues:

Update to version 3.1 (bsc#1274715).

Security issues fixed:

- CVE-2026-26961: rack: greedy multipart boundary parsing can lead to parser differentials and WAF bypass
  (bsc#1261398).
- CVE-2026-26962: rack: improper unfolding of folded multipart headers can lead to downstream header injection and
  response splitting(bsc#1261471).
- CVE-2026-34763: rack: unescaped regex interpolation of configured root path can lead to root directory disclosure
  (bsc#1261406).
- CVE-2026-34230: rack: crafted `Accept-Encoding` headers can cause a denial of service (bsc#1261388).
- CVE-2026-34785: rack: prefix matching logic can lead to the exposure of unintended files under the static root
  (bsc#1261417).
- CVE-2026-34786: rack: URL-encoded path mismatch can lead to `header_rules` bypass (bsc#1261426).
- CVE-2026-34826: rack: missing individual byte range limit checks when parsing HTTP `Range` headers can lead to
  excessive resource consumption and a denial of service (bsc#1261436).
- CVE-2026-34829: rack: multipart parsing without `Content-Length` header can lead to unbounded chunked file uploads
  and a denial of service (bsc#1261447).
- CVE-2026-34230: rack: quadratic complexity when processing of wildcard `Accept-Encoding` headers can lead to a denial
  of service (bsc#1261388).
- CVE-2026-34830: rack: improper sanitization of the `X-Accel-Mapping` request header can lead to the exposure of
  unintended files via `X-Accel-Redirect` (bsc#1261458).
- CVE-2026-34831: rack: `Content-Length` header and body byte size mismatch when creating error responses can lead to
  incorrect HTTP response framing (bsc#1261466).

Other updates and bugfixes:

- Version 3.1:
  * Remove all errors and warnigs due to new Ruby and Ruby on Rails versions
- Version 2.28:
  * Set arch to unknown for Rancher based products (jsc#SCC-759)
  * Fix purge for large amount of systems (bsc#1262706)
  * Change data type to `MEDIUMTEXT` in profiles table (bsc#1268305)
  * Remove `proxy_byos` column
  * Fix race condition when no system matches (bsc#1268301)
  * Fix race condition for PAYG (bsc#1268149)
  * Fix race condition to update a system (bsc#1268303)
- Version 2.27:
  * Fix ReDoS vulnerability in `Addressable`
  * Fixes out-of-bounds read vulnerability in `rdiscount`


Patch instructions:

   To install this openSUSE security update use the suse recommended installation methods
   like YaST online_update or "zypper patch".
   Alternatively you can run the command listed for your product:

- openSUSE Leap 16.0

   zypper in -t patch openSUSE-Leap-16.0-1499=1

Package List:

- openSUSE Leap 16.0:

  ansible-rmt-server-3.1.0-160000.1.1
  rmt-server-3.1.0-160000.1.1
  rmt-server-config-3.1.0-160000.1.1
  rmt-server-pubcloud-3.1.0-160000.1.1

References:

  * https://www.suse.com/security/cve/CVE-2026-26961.html
  * https://www.suse.com/security/cve/CVE-2026-26962.html
  * https://www.suse.com/security/cve/CVE-2026-34230.html
  * https://www.suse.com/security/cve/CVE-2026-34763.html
  * https://www.suse.com/security/cve/CVE-2026-34785.html
  * https://www.suse.com/security/cve/CVE-2026-34786.html
  * https://www.suse.com/security/cve/CVE-2026-34826.html
  * https://www.suse.com/security/cve/CVE-2026-34829.html
  * https://www.suse.com/security/cve/CVE-2026-34830.html
  * https://www.suse.com/security/cve/CVE-2026-34831.html
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.