|
|
Log in / Subscribe / Register

SUSE alert openSUSE-SU-2026:20852-1 (roundcubemail)

From:  null@suse.de
To:  security-announce@lists.opensuse.org
Subject:  openSUSE-SU-2026:20852-1: important: Security update for roundcubemail
Date:  Mon, 01 Jun 2026 17:51:43 +0200
Message-ID:  <20260601155143.C4BC5FCEF@maintenance.suse.de>
Archive-link:  Article

openSUSE security update: security update for roundcubemail ------------------------------------------------------------- Announcement ID: openSUSE-SU-2026:20852-1 Rating: important References: * bsc#1266329 * bsc#1266331 * bsc#1266332 * bsc#1266333 * bsc#1266334 * bsc#1266335 * bsc#1266336 * bsc#1266337 Cross-References: * CVE-2026-48842 * CVE-2026-48843 * CVE-2026-48844 * CVE-2026-48845 * CVE-2026-48846 * CVE-2026-48847 * CVE-2026-48848 * CVE-2026-48849 Affected Products: openSUSE Leap 16.0 ------------------------------------------------------------- An update that solves 8 vulnerabilities and has 8 bug fixes can now be installed. Description: This update for roundcubemail fixes the following issues: Changes in roundcubemail: - update to 1.6.16 + Fix potential too long value in IMAP ID command (#10136) + Security: Fix stored XSS/HTML/CSS injection in subject field of the draft restore dialog [CVE-2026-48849] [bsc#1266337] + Security: Fix CSS injection bypass in HTML sanitizer via SVG 'animate attributeName="style"' [CVE-2026-48848] [bsc#1266336] + Security: Fix pre-auth SQL injection in virtuser_query plugin via preg_replace backslash escape bypass [CVE-2026-48842] [bsc#1266329] + Security: Fix SSRF bypass via specific local address URLs [CVE-2026-48843] [bsc#1266331] + Security: Fix bypass of remote image blocking via CSS var() [CVE-2026-48846] [bsc#1266334] + Security: Fix local/private URL fetch bypass when remote resources were not allowed [CVE-2026-48845] [bsc#1266333] + Security: Fix pre-auth arbitrary file delete via redis/memcache session poisoning bypass [CVE-2026-48847] [bsc#1266335] + Security: Fix code injection vulnerability - remove support for code evaluation in LDAP autovalues option [CVE-2026-48844] [bsc#1266332] Patch instructions: To install this openSUSE security update use the suse recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Leap 16.0 zypper in -t patch openSUSE-Leap-16.0-packagehub-282=1 Package List: - openSUSE Leap 16.0: roundcubemail-1.6.16-bp160.1.1 References: * https://www.suse.com/security/cve/CVE-2026-48842.html * https://www.suse.com/security/cve/CVE-2026-48843.html * https://www.suse.com/security/cve/CVE-2026-48844.html * https://www.suse.com/security/cve/CVE-2026-48845.html * https://www.suse.com/security/cve/CVE-2026-48846.html * https://www.suse.com/security/cve/CVE-2026-48847.html * https://www.suse.com/security/cve/CVE-2026-48848.html * https://www.suse.com/security/cve/CVE-2026-48849.html


to post comments


Copyright © 2026, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds