FlawAtlas
Search the atlas
SUSE-RU-2026:2769-1 Not scored

Recommended update 5.1.4 for Multi-Linux Manager Salt Bundle

This update fixes the following issues: venv-salt-minion: - CVE-2026-27459: large cookie value can lead to a buffer overflow (bsc#1259808) - CVE-2026-27448: unhandled exception can result in connection not being cancelled (bsc#1259804) - Improved shutdown reliability when the salt-master/minion is terminated - Fixed broken 'pkg.info_installed' after migration to salt.utils.timeutil - Calculate UUID grain for Xen PV guests (bsc#1255418) - Use non vendored tornado with Python 3.11 (bsc#1257583, bsc#1259700) - BDSA-2025-60810: Harden Tornado from invalid HTTP reason phrases - Read full URI from ldap pillar config (bsc#1254900)

Exploit probability Not scored
Published July 20, 2026
Required by Not available
Last source change July 21, 2026

02 / AFFECTED SOFTWARE

Affected packages

SUSE:Multi Linux Manager Tools SLE-15 venv-salt-minion
SUSE:Multi Linux Manager Tools SLE-Micro-5 venv-salt-minion

03 / CONNECTIONS

Connected vulnerabilities

04 / EVIDENCE

Source records

Open Source Vulnerabilities SUSE-RU-2026:2769-1

This update fixes the following issues: venv-salt-minion: - CVE-2026-27459: large cookie value can lead to a buffer overflow (bsc#1259808) - CVE-2026-27448: unhandled exception can result in connection not being cancelled (bsc#1259804) - Improved shutdown reliability when the salt-master/minion is terminated - Fixed broken 'pkg.info_installed' after migration to salt.utils.timeutil - Calculate UUID grain for Xen PV guests (bsc#1255418) - Use non vendored tornado with Python 3.11 (bsc#1257583, bsc#1259700) - BDSA-2025-60810: Harden Tornado from invalid HTTP reason phrases - Read full URI from ldap pillar config (bsc#1254900)

View original source

05 / REFERENCES

Further evidence