SUSE-CU-2026:7954-1: Security update of suse/rmt-server
sle-container-updates at lists.suse.com
sle-container-updates at lists.suse.com
Tue Aug 4 17:51:29 UTC 2026
SUSE Container Update Advisory: suse/rmt-server
-----------------------------------------------------------------
Container Advisory ID : SUSE-CU-2026:7954-1
Container Tags : suse/rmt-server:2 , suse/rmt-server:2.28 , suse/rmt-server:2.28-88.1 , suse/rmt-server:latest
Container Release : 88.1
Severity : important
Type : security
References : 1175825 1197771 1229655 1230111 1233529 1245309 1245310 1245311
1245314 1246197 1246974 1247498 1249191 1249348 1249367 1249375
1251264 1253757 1255731 1255732 1255733 1255734 1256105 1258045
1258049 1258054 1258080 1258081 1259362 1259363 1259364 1259365
1259377 1259845 1262144 1262631 1264971 1268402 1268407 1268409
1268413 1268415 1268416 1268417 1268420 1268422 1268427 1272164
1272165 1272166 1272167 1272168 1272169 1272171 CVE-2020-8927
CVE-2025-10148 CVE-2025-11563 CVE-2025-14017 CVE-2025-14524 CVE-2025-14819
CVE-2025-15079 CVE-2025-15224 CVE-2025-4877 CVE-2025-4878 CVE-2025-5318
CVE-2025-5372 CVE-2025-8114 CVE-2025-8277 CVE-2025-9086 CVE-2026-0964
CVE-2026-0965 CVE-2026-0966 CVE-2026-0967 CVE-2026-0968 CVE-2026-10536
CVE-2026-12064 CVE-2026-1965 CVE-2026-27135 CVE-2026-3731 CVE-2026-3783
CVE-2026-3784 CVE-2026-3805 CVE-2026-4873 CVE-2026-5958 CVE-2026-59843
CVE-2026-59844 CVE-2026-59845 CVE-2026-59846 CVE-2026-59847 CVE-2026-59848
CVE-2026-59850 CVE-2026-8286 CVE-2026-8458 CVE-2026-8924 CVE-2026-8927
CVE-2026-9079 CVE-2026-9080 CVE-2026-9545 CVE-2026-9547
-----------------------------------------------------------------
The container suse/rmt-server was updated. The following patches have been included in this update:
-----------------------------------------------------------------
Advisory ID: SUSE-SU-2021:3942-1
Released: Mon Dec 6 14:46:05 2021
Summary: Security update for brotli
Type: security
Severity: moderate
References: 1175825,CVE-2020-8927
This update for brotli fixes the following issues:
- CVE-2020-8927: Fixed integer overflow when input chunk is larger than 2GiB (bsc#1175825).
-----------------------------------------------------------------
Advisory ID: SUSE-RU-2022:1658-1
Released: Fri May 13 15:40:20 2022
Summary: Recommended update for libpsl
Type: recommended
Severity: important
References: 1197771
This update for libpsl fixes the following issues:
- Fix libpsl compilation issues (bsc#1197771)
-----------------------------------------------------------------
Advisory ID: SUSE-RU-2024:3589-1
Released: Thu Oct 10 16:39:07 2024
Summary: Recommended update for cyrus-sasl
Type: recommended
Severity: moderate
References: 1230111
This update for cyrus-sasl fixes the following issues:
- Make DIGEST-MD5 work with openssl3 ( bsc#1230111 )
RC4 is legacy provided since openSSL3 and requires explicit loading, disable openssl3 depricated API warnings.
-----------------------------------------------------------------
Advisory ID: SUSE-SU-2025:2229-1
Released: Fri Jul 4 18:02:30 2025
Summary: Security update for libssh
Type: security
Severity: important
References: 1245309,1245310,1245311,1245314,CVE-2025-4877,CVE-2025-4878,CVE-2025-5318,CVE-2025-5372
This update for libssh fixes the following issues:
- CVE-2025-5318: Fixed likely read beyond bounds in sftp server handle management (bsc#1245311).
- CVE-2025-4877: Fixed write beyond bounds in binary to base64 conversion functions (bsc#1245309).
- CVE-2025-4878: Fixed use of uninitialized variable in privatekey_from_file() (bsc#1245310).
- CVE-2025-5372: Fixed cases where ssh_kdf() returns a success code on certain failures (bsc#1245314).
-----------------------------------------------------------------
Advisory ID: SUSE-RU-2025:2301-1
Released: Mon Jul 14 11:48:57 2025
Summary: Recommended update for cyrus-sasl
Type: recommended
Severity: moderate
References: 1229655
This update for cyrus-sasl fixes the following issues:
- Add Channel Binding support for GSSAPI/GSS-SPNEGO (bsc#1229655, jsc#PED-12097)
- Add support for setting max ssf 0 to GSS-SPNEGO (bsc#1229655, jsc#PED-12097).
-----------------------------------------------------------------
Advisory ID: SUSE-SU-2025:3268-1
Released: Thu Sep 18 13:08:10 2025
Summary: Security update for curl
Type: security
Severity: important
References: 1246197,1249191,1249348,1249367,CVE-2025-10148,CVE-2025-9086
This update for curl fixes the following issues:
Security issues fixed:
- CVE-2025-9086: bug in patch comparison logic when processing cookies can lead to out-of-bounds read in heap buffer
(bsc#1249191).
- CVE-2025-10148: predictable websocket mask can lead to proxy cache poisoning by malicious server (bsc#1249348).
Other issues fixed:
- Fix the --ftp-pasv option in curl v8.14.1 (bsc#1246197).
* tool_getparam: fix --ftp-pasv [5f805ee]
- Update to version 8.14.1 (jsc#PED-13055, jsc#PED-13056).
* TLS: add CURLOPT_SSL_SIGNATURE_ALGORITHMS and --sigalgs.
* websocket: add option to disable auto-pong reply.
* huge number of bugfixes.
Please see https://curl.se/ch/ for full changelogs.
-----------------------------------------------------------------
Advisory ID: SUSE-SU-2025:3369-1
Released: Fri Sep 26 12:54:43 2025
Summary: Security update for libssh
Type: security
Severity: moderate
References: 1246974,1249375,CVE-2025-8114,CVE-2025-8277
This update for libssh fixes the following issues:
- CVE-2025-8277: memory exhaustion leading to client-side DoS due to improper memory management when KEX process is
repeated with incorrect guesses (bsc#1249375).
- CVE-2025-8114: NULL pointer dereference when an allocation error happens during the calculation of the KEX session ID
(bsc#1246974).
-----------------------------------------------------------------
Advisory ID: SUSE-RU-2025:3596-1
Released: Wed Oct 15 09:51:21 2025
Summary: Recommended update for curl
Type: recommended
Severity: moderate
References: 1251264
This update for curl fixes the following issue:
- rebuilds it against a newer nghttp2 to fix handling 2 or more whitespaces in headers. (bsc#1251264)
-----------------------------------------------------------------
Advisory ID: SUSE-RU-2025:3934-1
Released: Tue Nov 4 12:23:11 2025
Summary: Recommended update for cyrus-sasl
Type: recommended
Severity: moderate
References: 1247498
This update for cyrus-sasl fixes the following issue:
- Replace insecure MD5 with ephemeral HMAC-SHA256 (bsc#1247498).
-----------------------------------------------------------------
Advisory ID: SUSE-RU-2025:4155-1
Released: Fri Nov 21 15:09:44 2025
Summary: Recommended update for cyrus-sasl
Type: recommended
Severity: moderate
References: 1233529
This update for cyrus-sasl fixes the following issues:
- Python3 error log upon importing pycurl (bsc#1233529)
* Remove senceless log message.
-----------------------------------------------------------------
Advisory ID: SUSE-SU-2025:4300-1
Released: Fri Nov 28 13:57:41 2025
Summary: Security update for curl
Type: security
Severity: moderate
References: 1253757,CVE-2025-11563
This update for curl fixes the following issues:
- CVE-2025-11563: Fixed wcurl path traversal with percent-encoded slashes (bsc#1253757)
-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:52-1
Released: Wed Jan 7 10:28:34 2026
Summary: Security update for curl
Type: security
Severity: moderate
References: 1255731,1255732,1255733,1255734,CVE-2025-14524,CVE-2025-14819,CVE-2025-15079,CVE-2025-15224
This update for curl fixes the following issues:
- CVE-2025-14524: bearer token leak on cross-protocol redirect (bsc#1255731).
- CVE-2025-14819: libssh global knownhost override (bsc#1255732).
- CVE-2025-15079: libssh key passphrase bypass without agent set (bsc#1255733).
- CVE-2025-15224: OpenSSL partial chain store policy bypass (bsc#1255734).
-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:221-1
Released: Thu Jan 22 13:15:35 2026
Summary: Security update for curl
Type: security
Severity: moderate
References: 1256105,CVE-2025-14017
This update for curl fixes the following issues:
- CVE-2025-14017: Fixed broken TLS options for threaded LDAPS (bsc#1256105).
-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:779-1
Released: Tue Mar 3 14:25:07 2026
Summary: Security update for libssh
Type: security
Severity: moderate
References: 1258045,1258049,1258054,1258080,1258081,CVE-2026-0964,CVE-2026-0965,CVE-2026-0966,CVE-2026-0967,CVE-2026-0968
This update for libssh fixes the following issues:
- CVE-2026-0964: improper sanitation of paths received from SCP servers can cause path traversal (bsc#1258049).
- CVE-2026-0965: possible denial of service when parsing unexpected configuration files (bsc#1258045).
- CVE-2026-0966: buffer underflow in ssh_get_hexa() on invalid input (bsc#1258054).
- CVE-2026-0967: specially crafted patterns could cause denial of service (bsc#1258081).
- CVE-2026-0968: malformed SFTP message can lead to out of bound read (bsc#1258080).
-----------------------------------------------------------------
Advisory ID: SUSE-RU-2026:863-1
Released: Wed Mar 11 13:41:48 2026
Summary: Recommended update for openldap2
Type: recommended
Severity: moderate
References:
This update for openldap2 fixes the following issues:
- expose ldap_log.h in -devel (jsc#PED-15735)
-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:903-1
Released: Tue Mar 17 11:04:44 2026
Summary: Security update for curl
Type: security
Severity: important
References: 1259362,1259363,1259364,1259365,CVE-2026-1965,CVE-2026-3783,CVE-2026-3784,CVE-2026-3805
This update for curl fixes the following issues:
- CVE-2026-1965: bad reuse of HTTP Negotiate connection (bsc#1259362).
- CVE-2026-3783: token leak with redirect and netrc (bsc#1259363).
- CVE-2026-3784: wrong proxy connection reuse with credentials (bsc#1259364).
- CVE-2026-3805: use after free in SMB connection reuse (bsc#1259365).
-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:1074-1
Released: Thu Mar 26 13:39:49 2026
Summary: Security update for nghttp2
Type: security
Severity: important
References: 1259845,CVE-2026-27135
This update for nghttp2 fixes the following issues:
- CVE-2026-27135: Assertion failure due to missing state validation can lead to DoS (bsc#1259845).
-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:1310-1
Released: Tue Apr 14 12:42:12 2026
Summary: Security update for libssh
Type: security
Severity: moderate
References: 1259377,CVE-2026-3731
This update for libssh fixes the following issues:
- CVE-2026-3731: Denial of Service via out-of-bounds read in SFTP extension name handler (bsc#1259377).
-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:1941-1
Released: Mon May 18 09:44:34 2026
Summary: Security update for sed
Type: security
Severity: moderate
References: 1262144,CVE-2026-5958
This update for sed fixes the following issue:
- CVE-2026-5958: a TOCTOU race can allow to read attacker-controlled content and write it to an unintended file (bsc#1262144).
-----------------------------------------------------------------
Advisory ID: SUSE-RU-2026:2661-1
Released: Fri Jun 26 15:15:48 2026
Summary: Recommended update for curl
Type: recommended
Severity: important
References: 1264971
This update for curl fixes the following issues:
- Call http_size() first to prioritize Transfer-Encoding: chunked over a zero
Content-Length empty body check (bsc#1264971)
-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:2925-1
Released: Mon Jul 13 19:53:23 2026
Summary: Security update for curl
Type: security
Severity: important
References: 1262631,1268402,1268407,1268409,1268413,1268415,1268416,1268417,1268420,1268422,1268427,CVE-2026-10536,CVE-2026-12064,CVE-2026-4873,CVE-2026-8286,CVE-2026-8458,CVE-2026-8924,CVE-2026-8927,CVE-2026-9079,CVE-2026-9080,CVE-2026-9545,CVE-2026-9547
This update for curl fixes the following issues
- CVE-2026-4873: connection reuse ignores TLS requirement (bsc#1262631).
- CVE-2026-8286: wrong STARTTLS connection reuse (bsc#1268402).
- CVE-2026-8458: wrong reuse for different services (bsc#1268407).
- CVE-2026-8924: traling dot domain super cookie (bsc#1268409).
- CVE-2026-8927: env-set cross-proxy Digest auth state leak (bsc#1268413).
- CVE-2026-9079: stale proxy password leak (bsc#1268415).
- CVE-2026-9080: UAF after pause in socket callback (bsc#1268416).
- CVE-2026-9545: exposing HTTP/3 early data (bsc#1268417).
- CVE-2026-9547: SSH improper host validation (bsc#1268420).
- CVE-2026-10536: HTTP/2 stream-dependency tree UAF (bsc#1268422).
- CVE-2026-12064: proto-default skips SSH verification (bsc#1268427).
-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:3330-1
Released: Tue Jul 28 11:35:51 2026
Summary: Security update for libssh
Type: security
Severity: moderate
References: 1272164,1272165,1272166,1272167,1272168,1272169,1272171,CVE-2026-59843,CVE-2026-59844,CVE-2026-59845,CVE-2026-59846,CVE-2026-59847,CVE-2026-59848,CVE-2026-59850
This update for libssh fixes the following issues:
- CVE-2026-59843: denial of service via zero advertised channel packet size (bsc#1272164).
- CVE-2026-59844: denial of service via oversized SFTP read length (bsc#1272165).
- CVE-2026-59845: denial of service via unchecked ProxyCommand fork() failure (bsc#1272166).
- CVE-2026-59846: information disclosure via ProxyCommand %r username expansion (bsc#1272167).
- CVE-2026-59847: integrity downgrade via OpenSSL AES-GCM tag verification (bsc#1272168).
- CVE-2026-59848: denial of service via SFTP responses with unknown request IDs (bsc#1272169).
- CVE-2026-59850: use-after-free via data callbacks on closed channels (bsc#1272171).
The following package changes have been done:
- libbrotlicommon1-1.0.7-150200.3.5.1 added
- libldap-data-2.4.46-150600.25.3.1 added
- libnghttp2-14-1.64.0-150700.3.3.1 added
- libsasl2-3-2.1.28-150600.7.14.1 added
- libssh-config-0.9.8-150600.11.15.1 added
- libunistring2-0.9.10-1.1 added
- libzstd1-1.5.7-150700.1.2 added
- sed-4.9-150600.3.3.1 added
- libbrotlidec1-1.0.7-150200.3.5.1 added
- libidn2-0-2.2.0-3.6.1 added
- libpsl5-0.20.1-150000.3.3.1 added
- libldap-2_4-2-2.4.46-150600.25.3.1 added
- libssh4-0.9.8-150600.11.15.1 added
- libcurl4-8.14.1-150700.7.20.1 added
- container:suse-sle15-15.7-a5e0c95d4920d65d037fe2ab91c98c6e7c6b609d46ff4844855cbfe5770934aa-0 added
- container:registry.suse.com-bci-bci-micro-15.7-4cdcad941236068fdf4cac1f3008600d478ebbf78236677452a662ae1f3fe792-0 added
- bash-sh-4.4-150400.27.6.1 removed
- container:registry.suse.com-bci-bci-base-15.7-0411096f465658d23cf7197d39261fa8d818d8fc75c5ad5ce0e68f97a657663f-0 removed
- coreutils-8.32-150400.9.12.1 removed
- filesystem-15.0-11.8.1 removed
- glibc-2.38-150600.14.52.1 removed
- libacl1-2.2.52-4.3.1 removed
- libattr1-2.4.47-2.19 removed
- libcap2-2.63-150400.3.6.1 removed
- libgcc_s1-15.3.0+git11272-150000.1.12.1 removed
- libgmp10-6.1.2-4.9.1 removed
- libncurses6-6.1-150000.5.33.1 removed
- libopenssl-3-fips-provider-3.2.3-150700.5.36.1 removed
- libpcre2-8-0-10.42-150600.1.26 removed
- libreadline7-7.0-150400.27.6.1 removed
- libselinux1-3.5-150600.3.3.1 removed
- libstdc++6-15.3.0+git11272-150000.1.12.1 removed
- patterns-base-fips-20200124-150700.36.1 removed
- system-user-root-20190513-3.3.1 removed
- terminfo-base-6.1-150000.5.33.1 removed
More information about the sle-container-updates
mailing list