Alerts This Week
Warning Icon 1 640
Alerts This Week
Warning Icon 1 640

openSUSE RMT-Server Important Denial of Service Fix SUSE-SU-2026-1964-1

opensuse
Calendar Grey May 18, 2026
Dist Opensuse Esm H88
Security update for openSUSE addresses 10 issues in rmt-server. Important fix for denial of service vulnerabilities.
An update that solves 10 vulnerabilities and has one security fix can now be installed.

Description

This update for rmt-server fixes the following issues

* CVE-2026-26961: rack: mismatch in header handling can allow to smuggle

multipart content (bsc#1261398).

* CVE-2026-26962: rack: improper unfolding of folded multipart headers can

lead to header injection or response splitting (bsc#1261471).

* CVE-2026-34230: rack: crafted Accept-Encoding header can cause a denial of

service (bsc#1261388).

* CVE-2026-34763: rack: failing of the prefix stripping can lead to

information disclosure (bsc#1261406).

* CVE-2026-34785: rack: prefix matching can expose unintended files under the

static root (bsc#1261417).

* CVE-2026-34786: rack: URL-encoded path mismatch can lead to `header_rules`

bypass (bsc#1261426).

* CVE-2026-34826: rack: multipart byte range processing can allow denial of

service (bsc#1261436).

* CVE-2026-34829: rack: multipart parsing without `Content-Length` header

allows unbounded chunked file uploads (bsc#1261447).

*...

Read the Full Advisory

Patch

## Patch Instructions:

To install this SUSE update use the SUSE recommended installation methods like

YaST online_update or "zypper patch".

Alternatively you can run the command listed for your product:

* openSUSE Leap 15.4

zypper in -t patch SUSE-2026-1964=1

* Public Cloud Module 15-SP4

zypper in -t patch SUSE-SLE-Module-Public-Cloud-15-SP4-2026-1964=1

* SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4

zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-ESPOS-2026-1964=1

* SUSE Linux Enterprise High Performance Computing LTSS 15 SP4

zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-LTSS-2026-1964=1

* SUSE Linux Enterprise Server 15 SP4 LTSS

zypper in -t patch SUSE-SLE-Product-SLES-15-SP4-LTSS-2026-1964=1

* SUSE Linux Enterprise Server for SAP Applications 15 SP4

zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP4-2026-1964=1

Package List

* openSUSE Leap 15.4 (aarch64 ppc64le s390x x86_64)

* rmt-server-pubcloud-2.27-150400.3.54.1

* rmt-server-2.27-150400.3.54.1

* rmt-server-debuginfo-2.27-150400.3.54.1

* rmt-server-debugsource-2.27-150400.3.54.1

* rmt-server-config-2.27-150400.3.54.1

* Public Cloud Module 15-SP4 (aarch64 ppc64le s390x x86_64)

* rmt-server-debuginfo-2.27-150400.3.54.1

* rmt-server-debugsource-2.27-150400.3.54.1

* rmt-server-pubcloud-2.27-150400.3.54.1

* SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (aarch64

x86_64)

* rmt-server-debuginfo-2.27-150400.3.54.1

* rmt-server-config-2.27-150400.3.54.1

* rmt-server-debugsource-2.27-150400.3.54.1

* rmt-server-2.27-150400.3.54.1

* SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (aarch64

x86_64)

* rmt-server-debuginfo-2.27-150400.3.54.1

* rmt-server-config-2.27-150400.3.54.1

* rmt-server-debugsource-2.27-150400.3.54.1

* rmt-server-2.27-150400.3.54.1

* SUSE Linux Enterprise Server 15 SP4 LTSS (aarch64 ppc64le s390x x86_64)

*...

Read the Full Advisory

References

* bsc#1246976

* bsc#1261388

* bsc#1261398

* bsc#1261406

* bsc#1261417

* bsc#1261426

* bsc#1261436

* bsc#1261447

* bsc#1261458

* bsc#1261466

* bsc#1261471

## References:

* https://www.suse.com/security/cve/CVE-2026-26961.html

* https://www.suse.com/security/cve/CVE-2026-26962.html

* https://www.suse.com/security/cve/CVE-2026-34230.html

* https://www.suse.com/security/cve/CVE-2026-34763.html

* https://www.suse.com/security/cve/CVE-2026-34785.html

* https://www.suse.com/security/cve/CVE-2026-34786.html

* https://www.suse.com/security/cve/CVE-2026-34826.html

* https://www.suse.com/security/cve/CVE-2026-34829.html

* https://www.suse.com/security/cve/CVE-2026-34830.html

* https://www.suse.com/security/cve/CVE-2026-34831.html

* https://bugzilla.suse.com/show_bug.cgi?id=1246976

* https://bugzilla.suse.com/show_bug.cgi?id=1261388

* https://bugzilla.suse.com/show_bug.cgi?id=1261398

* https://bugzilla.suse.com/show_bug.cgi?id=1261406

* https://bugzilla.suse.com/show_bug.cgi?id=1261417

*...

Read the Full Advisory

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2026:1964-1
Release Date: 2026-05-18T08:10:10Z
Affected Products: * openSUSE Leap 15.4 * Public Cloud Module 15-SP4 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP4 LTSS * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Manager Proxy 4.3 * SUSE Manager Retail Branch Server 4.3 * SUSE Manager Server 4.3

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here