{"id":"openSUSE-SU-2026:21225-1","summary":"Security update for rmt-server","details":"This update for rmt-server fixes the following issue\n\nUpdate to 3.0.0:\n\n- CVE-2026-42256: net-imap: hostile server can perform a DoS on client authenticating a connection with SCRAM-SHA1 or\n  SCRAM-SHA2 (bsc#1265369).\n\nChanges for rmt-server:\n\n- Version 3.0.0\n * Security fix: Remove unused ActionMailer/ActionMailbox components to\n eliminate CVE-2026-42256 (bsc#1265369)\n * Split Rails meta-gem into individual components for better security control\n- Version 2.26\n * Add support for processing, storing, and syncing system profiles (jsc#TEL-265)\n- Version 2.25\n * fix rmt-cli list and purge commands for large data (bsc#1253146 and bsc#1253147)\n * Fix mirroring of SLE16 NVIDIA-GPU-Compute-Toolkit-CUDA repo (bsc#1256826)\n * Support for new redirect_repo_hosts config, to exclude some repo hosts\n from mirroring, and send clients directly there (jsc#SCC-452)\n * rmt-server-pubcloud\n * Clearer error message (bsc#1256883)\n * Handle zypper response when data exporter raises an error (bsc#1257133)\n * Add Valkey + Sidekiq for async processing\n * Enable mirroring xz compressed repositories (bsc#1246976)\n * Rack 2.2.20 security update (bsc#1253953, bsc#1251937)\n * Drop some de-published products from RMT\n * Include Live-Patching for SLES 15.X (jsc#PCT-630)\n * Handle only one data exporter (bsc#1248869)\n * Do not decode instance data from db to access registry (bsc#1248510)\n * Handle instance verification exceptions\n","modified":"2026-07-05T18:24:20.444490413Z","published":"2026-07-03T11:05:43Z","related":["CVE-2026-42256"],"upstream":["CVE-2026-42256"],"references":[{"type":"ADVISORY"},{"type":"REPORT","url":"https://bugzilla.suse.com/1246976"},{"type":"REPORT","url":"https://bugzilla.suse.com/1248510"},{"type":"REPORT","url":"https://bugzilla.suse.com/1248869"},{"type":"REPORT","url":"https://bugzilla.suse.com/1251937"},{"type":"REPORT","url":"https://bugzilla.suse.com/1253146"},{"type":"REPORT","url":"https://bugzilla.suse.com/1253147"},{"type":"REPORT","url":"https://bugzilla.suse.com/1253953"},{"type":"REPORT","url":"https://bugzilla.suse.com/1256826"},{"type":"REPORT","url":"https://bugzilla.suse.com/1256883"},{"type":"REPORT","url":"https://bugzilla.suse.com/1257133"},{"type":"REPORT","url":"https://bugzilla.suse.com/1265369"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-42256"}],"affected":[{"package":{"name":"rmt-server","ecosystem":"openSUSE:Leap 16.0","purl":"pkg:rpm/opensuse/rmt-server&distro=openSUSE%20Leap%2016.0"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"3.0.0-160000.1.1"}]}],"ecosystem_specific":{"binaries":[{"ansible-rmt-server":"3.0.0-160000.1.1","rmt-server":"3.0.0-160000.1.1","rmt-server-config":"3.0.0-160000.1.1","rmt-server-pubcloud":"3.0.0-160000.1.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2026:21225-1.json"}}],"schema_version":"1.7.5"}