Security update 5.1.2 for Multi-Linux Manager Salt Bundle
This update fixes the following issues: venv-salt-minion: - Backport security patches for Salt vendored tornado: * CVE-2025-67724: missing validation of supplied reason phrase (bsc#1254903) * CVE-2025-67725: fix DoS via malicious HTTP request (bsc#1254905) * CVE-2025-67726: fix HTTP header parameter parsing algorithm (bsc#1254904) - Make syntax in httputil_test compatible with Python 3.6 - Fix KeyError in postgres module with PostgreSQL 17 (bsc#1254325) - Use internal deb classes instead of external aptsource lib - Speed up wheel key.finger call (bsc#1240532) - Simplify and speed up utils.find_json function (bsc#1246130) - Extend warn_until period to 2027
02 / AFFECTED SOFTWARE
Affected packages
03 / CONNECTIONS
Connected vulnerabilities
04 / EVIDENCE
Source records
This update fixes the following issues: venv-salt-minion: - Backport security patches for Salt vendored tornado: * CVE-2025-67724: missing validation of supplied reason phrase (bsc#1254903) * CVE-2025-67725: fix DoS via malicious HTTP request (bsc#1254905) * CVE-2025-67726: fix HTTP header parameter parsing algorithm (bsc#1254904) - Make syntax in httputil_test compatible with Python 3.6 - Fix KeyError in postgres module with PostgreSQL 17 (bsc#1254325) - Use internal deb classes instead of external aptsource lib - Speed up wheel key.finger call (bsc#1240532) - Simplify and speed up utils.find_json function (bsc#1246130) - Extend warn_until period to 2027
05 / REFERENCES
Further evidence
- https://bugzilla.suse.com/1240532
- https://bugzilla.suse.com/1246130
- https://bugzilla.suse.com/1254325
- https://bugzilla.suse.com/1254903
- https://bugzilla.suse.com/1254904
- https://bugzilla.suse.com/1254905
- https://www.suse.com/security/cve/CVE-2025-67724
- https://www.suse.com/security/cve/CVE-2025-67725
- https://www.suse.com/security/cve/CVE-2025-67726
- https://www.suse.com/support/update/announcement/2026/suse-su-20260629-1/