FlawAtlas
Search the atlas
SUSE-SU-2026:1026-1 Not scored

Security update 5.0.7 for Multi-Linux Manager Salt Bundle

This update fixes the following issues: venv-salt-minion: - Security issues fixed: * CVE-2025-67724: fixed missing validation of supplied reason phrase (bsc#1254903) * CVE-2025-67725: fixed DoS via malicious HTTP request (bsc#1254905) * CVE-2025-67726: fixed HTTP header parameter parsing algorithm (bsc#1254904) * CVE-2025-62349: Added minimum_auth_version to enforce security (bsc#1254257) * CVE-2025-62348: Fixed Junos module yaml loader (bsc#1254256) * CVE-2025-13836: Set a safe limit to http.client response read (bsc#1254400) - Fixed KeyError in postgres module with PostgreSQL 17 (bsc#1254325) - Use internal deb classes instead of external aptsource lib - Improved performance of wheel key.finger call (bsc#1240532) - Improved performance of utils.find_json function (bsc#1246130) - Extended warn_until period to 2027

Exploit probability Not scored
Published March 25, 2026
Required by Not available
Last source change March 26, 2026

02 / AFFECTED SOFTWARE

Affected packages

SUSE:EL-9:Update:Products:SaltBundle:Update saltbundlepy
SUSE:EL-9:Update:Products:SaltBundle:Update saltbundlepy-core
SUSE:EL-9:Update:Products:SaltBundle:Update saltbundlepy-m2crypto
SUSE:EL-9:Update:Products:SaltBundle:Update saltbundlepy-passlib
SUSE:EL-9:Update:Products:SaltBundle:Update saltbundlepy-passlib-test
SUSE:EL-9:Update:Products:SaltBundle:Update saltbundlepy-pyasn1
SUSE:EL-9:Update:Products:SaltBundle:Update saltbundlepy-pyzmq
SUSE:EL-9:Update:Products:SaltBundle:Update saltbundlepy-simplejson
SUSE:EL-9:Update:Products:SaltBundle:Update saltbundlepy-tornado
SUSE:EL-9:Update:Products:SaltBundle:Update saltbundlepy-websocket-client
SUSE:EL-9:Update:Products:SaltBundle:Update venv-salt-minion
SUSE:Manager Client Tools for RHEL, Liberty and Clones 9-CLIENT-TOOLS venv-salt-minion

03 / CONNECTIONS

Connected vulnerabilities

04 / EVIDENCE

Source records

Open Source Vulnerabilities SUSE-SU-2026:1026-1

This update fixes the following issues: venv-salt-minion: - Security issues fixed: * CVE-2025-67724: fixed missing validation of supplied reason phrase (bsc#1254903) * CVE-2025-67725: fixed DoS via malicious HTTP request (bsc#1254905) * CVE-2025-67726: fixed HTTP header parameter parsing algorithm (bsc#1254904) * CVE-2025-62349: Added minimum_auth_version to enforce security (bsc#1254257) * CVE-2025-62348: Fixed Junos module yaml loader (bsc#1254256) * CVE-2025-13836: Set a safe limit to http.client response read (bsc#1254400) - Fixed KeyError in postgres module with PostgreSQL 17 (bsc#1254325) - Use internal deb classes instead of external aptsource lib - Improved performance of wheel key.finger call (bsc#1240532) - Improved performance of utils.find_json function (bsc#1246130) - Extended warn_until period to 2027

View original source

05 / REFERENCES

Further evidence