Описание
Security update for rmt-server
This update for rmt-server fixes the following issue
Update to 3.0.0:
- CVE-2026-42256: net-imap: hostile server can perform a DoS on client authenticating a connection with SCRAM-SHA1 or SCRAM-SHA2 (bsc#1265369).
Changes for rmt-server:
- Version 3.0.0
- Security fix: Remove unused ActionMailer/ActionMailbox components to eliminate CVE-2026-42256 (bsc#1265369)
- Split Rails meta-gem into individual components for better security control
- Version 2.26
- Add support for processing, storing, and syncing system profiles (jsc#TEL-265)
- Version 2.25
- fix rmt-cli list and purge commands for large data (bsc#1253146 and bsc#1253147)
- Fix mirroring of SLE16 NVIDIA-GPU-Compute-Toolkit-CUDA repo (bsc#1256826)
- Support for new redirect_repo_hosts config, to exclude some repo hosts from mirroring, and send clients directly there (jsc#SCC-452)
- rmt-server-pubcloud
- Clearer error message (bsc#1256883)
- Handle zypper response when data exporter raises an error (bsc#1257133)
- Add Valkey + Sidekiq for async processing
- Enable mirroring xz compressed repositories (bsc#1246976)
- Rack 2.2.20 security update (bsc#1253953, bsc#1251937)
- Drop some de-published products from RMT
- Include Live-Patching for SLES 15.X (jsc#PCT-630)
- Handle only one data exporter (bsc#1248869)
- Do not decode instance data from db to access registry (bsc#1248510)
- Handle instance verification exceptions
Список пакетов
openSUSE Leap 16.0
ansible-rmt-server-3.0.0-160000.1.1
rmt-server-3.0.0-160000.1.1
rmt-server-config-3.0.0-160000.1.1
rmt-server-pubcloud-3.0.0-160000.1.1
Ссылки
- SUSE Security Ratings
- SUSE Bug 1246976
- SUSE Bug 1248510
- SUSE Bug 1248869
- SUSE Bug 1251937
- SUSE Bug 1253146
- SUSE Bug 1253147
- SUSE Bug 1253953
- SUSE Bug 1256826
- SUSE Bug 1256883
- SUSE Bug 1257133
- SUSE Bug 1265369
- SUSE CVE CVE-2026-42256 page
Описание
Net::IMAP implements Internet Message Access Protocol (IMAP) client functionality in Ruby. From versions 0.4.0 to before 0.4.24, 0.5.0 to before 0.5.14, and 0.6.0 to before 0.6.4, when authenticating a connection with SCRAM-SHA1 or SCRAM-SHA256, a hostile server can perform a computational denial-of-service attack on the client process by sending a big iteration count value. This issue has been patched in versions 0.4.24, 0.5.14, and 0.6.4.
Затронутые продукты
openSUSE Leap 16.0:ansible-rmt-server-3.0.0-160000.1.1
openSUSE Leap 16.0:rmt-server-3.0.0-160000.1.1
openSUSE Leap 16.0:rmt-server-config-3.0.0-160000.1.1
openSUSE Leap 16.0:rmt-server-pubcloud-3.0.0-160000.1.1
Ссылки
- CVE-2026-42256
- SUSE Bug 1265366