SUSE-CU-2026:8768-1: Security update of suse/rmt-server

sle-container-updates at lists.suse.com sle-container-updates at lists.suse.com
Sat Aug 15 07:40:39 UTC 2026


SUSE Container Update Advisory: suse/rmt-server
-----------------------------------------------------------------
Container Advisory ID : SUSE-CU-2026:8768-1
Container Tags        : suse/rmt-server:2 , suse/rmt-server:2.28 , suse/rmt-server:2.28-88.7 , suse/rmt-server:latest
Container Release     : 88.7
Severity              : important
Type                  : security
References            : 1262441 1271712 CVE-2026-41316 
-----------------------------------------------------------------

The container suse/rmt-server was updated. The following patches have been included in this update:

-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:3556-1
Released:    Mon Aug 10 19:56:42 2026
Summary:     Security update for ruby2.5
Type:        security
Severity:    important
References:  1262441,CVE-2026-41316
This update for ruby2.5 fixes the following issue

- CVE-2026-41316: erb: @_init deserialization guard bypass via def_module / def_method / def_class (bsc#1262441).

-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:3578-1
Released:    Tue Aug 11 15:58:41 2026
Summary:     Security update for openssl-1_1
Type:        security
Severity:    moderate
References:  1271712
This update for openssl-1_1 fixes the following issues:

- HollowByte: DoS vector against OpenSSL TLS ClientHello via remote, attacker-controlled memory allocations
  (bsc#1271712).

-----------------------------------------------------------------
Advisory ID: SUSE-RU-2026:3582-1
Released:    Tue Aug 11 16:35:48 2026
Summary:     Recommended update for timezone
Type:        recommended
Severity:    moderate
References:  
This update for timezone fixes the following issues:

- Update to 2026c:
    * Alberta moved to permanent -06 on 2026-06-18.
    * Morocco moves to permanent +00 on 2026-09-20.
    * More integer overflow bugs have been fixed in zic.


The following package changes have been done:

- timezone-2026c-150600.91.12.1 updated
- libruby2_5-2_5-2.5.9-150700.24.11.1 updated
- libopenssl1_1-1.1.1w-150700.11.25.2 updated
- ruby2.5-stdlib-2.5.9-150700.24.11.1 updated
- ruby2.5-2.5.9-150700.24.11.1 updated
- container:suse-sle15-15.7-cf4c66d3369e1cf8626eac5ede03500dbc2d4b9d48db2ffa77a09d3d4ca82254-0 updated


More information about the sle-container-updates mailing list