Security update 5.0.7 for Multi-Linux Manager Salt Bundle
This update fixes the following issues: venv-salt-minion: - Security issues fixed: * CVE-2025-67724: Fixed missing validation of supplied reason phrase (bsc#1254903) * CVE-2025-67725: Fixed DoS via malicious HTTP request (bsc#1254905) * CVE-2025-67726: Fixed HTTP header parameter parsing algorithm (bsc#1254904) * CVE-2025-62349: Added minimum_auth_version to enforce security (bsc#1254257) * CVE-2025-62348: Fixed Junos module yaml loader (bsc#1254256) * CVE-2025-13836: Set a safe limit to http.client response read (bsc#1254400) - Fixed KeyError in postgres module with PostgreSQL 17 (bsc#1254325) - Use internal deb classes instead of external aptsource lib - Improved performance of wheel key.finger call (bsc#1240532) - Improved performance of utils.find_json function (bsc#1246130) - Extended warn_until period to 2027
02 / AFFECTED SOFTWARE
Affected packages
03 / CONNECTIONS
Connected vulnerabilities
04 / EVIDENCE
Source records
This update fixes the following issues: venv-salt-minion: - Security issues fixed: * CVE-2025-67724: Fixed missing validation of supplied reason phrase (bsc#1254903) * CVE-2025-67725: Fixed DoS via malicious HTTP request (bsc#1254905) * CVE-2025-67726: Fixed HTTP header parameter parsing algorithm (bsc#1254904) * CVE-2025-62349: Added minimum_auth_version to enforce security (bsc#1254257) * CVE-2025-62348: Fixed Junos module yaml loader (bsc#1254256) * CVE-2025-13836: Set a safe limit to http.client response read (bsc#1254400) - Fixed KeyError in postgres module with PostgreSQL 17 (bsc#1254325) - Use internal deb classes instead of external aptsource lib - Improved performance of wheel key.finger call (bsc#1240532) - Improved performance of utils.find_json function (bsc#1246130) - Extended warn_until period to 2027
05 / REFERENCES
Further evidence
- https://bugzilla.suse.com/1240532
- https://bugzilla.suse.com/1246130
- https://bugzilla.suse.com/1254256
- https://bugzilla.suse.com/1254257
- https://bugzilla.suse.com/1254325
- https://bugzilla.suse.com/1254400
- https://bugzilla.suse.com/1254903
- https://bugzilla.suse.com/1254904
- https://bugzilla.suse.com/1254905
- https://www.suse.com/security/cve/CVE-2025-13836
- https://www.suse.com/security/cve/CVE-2025-62348
- https://www.suse.com/security/cve/CVE-2025-62349
- https://www.suse.com/security/cve/CVE-2025-67724
- https://www.suse.com/security/cve/CVE-2025-67725
- https://www.suse.com/security/cve/CVE-2025-67726
- https://www.suse.com/support/update/announcement/2026/suse-su-20261012-1/