{"id":"SUSE-SU-2026:3792-1","summary":"Security update for rmt-server","details":"This update for rmt-server fixes the following issue:\n\nUpdate to version 3.1 (bsc#1274715).\n\n- CVE-2026-42256: net-imap: hostile server can perform a DoS on client authenticating a connection with SCRAM-SHA1 or\n  SCRAM-SHA2 (bsc#1265369).\n\nChanges for rmt-server:\n\n- Version 3.1:\n  * Remove all errors and warnings due to new Ruby and Ruby on Rails versions\n- Version 3.0:\n  * Split Rails meta-gem into individual components for better security control\n- Version 3.0.alpha:\n  * Update Ruby to version 3.4.8 and Rails to version 7.1.6\n","modified":"2026-08-27T11:00:09.048436760Z","published":"2026-08-25T12:31:31Z","related":["CVE-2026-42256"],"upstream":["CVE-2026-42256"],"references":[{"type":"ADVISORY","url":"https://www.suse.com/support/update/announcement/2026/suse-su-20263792-1/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1265369"},{"type":"REPORT","url":"https://bugzilla.suse.com/1274715"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-42256"}],"affected":[{"package":{"name":"rmt-server","ecosystem":"SUSE:Linux Enterprise Module for Public Cloud 15 SP7","purl":"pkg:rpm/suse/rmt-server&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Public%20Cloud%2015%20SP7"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"3.1.0-150700.3.28.1"}]}],"ecosystem_specific":{"binaries":[{"rmt-server-pubcloud":"3.1.0-150700.3.28.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:3792-1.json"}},{"package":{"name":"rmt-server","ecosystem":"SUSE:Linux Enterprise Module for Server Applications 15 SP7","purl":"pkg:rpm/suse/rmt-server&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Server%20Applications%2015%20SP7"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"3.1.0-150700.3.28.1"}]}],"ecosystem_specific":{"binaries":[{"rmt-server":"3.1.0-150700.3.28.1","rmt-server-config":"3.1.0-150700.3.28.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:3792-1.json"}}],"schema_version":"1.9.0"}