FlawAtlas
Search the atlas
SUSE-SU-2026:1146-1 Not scored

Security Beta update 5.2.0 Beta1 for Multi-Linux Manager Client Tools

This update fixes the following issues: mgr-push: - Version 5.2.3-0 * Disable build for SLES 16 rhnlib: - Version 5.2.4-0 * Disable build for SLES 16 spacecmd: - Version 5.2.6-0 * Update translation strings spacewalk-client-tools: - Version 5.2.4-0 * Disable build for SLES 16 uyuni-common-libs: - Version 5.2.3-0 * Disable build for SLES 16 uyuni-tools: - Version 5.2.5-0 * Remove migrate command * Remove template script from mgradm: use the one in the image * Split the TFTP server into a separate container * Explicitly start proxy pods after operations (bsc#1258015) * Adjust mgrctl server filter to work with the new helm chart labels * Remove hub register command * Remove the Kubernetes install and upgrade from mgrpxy * Optimize postgres migration disk space usage (bsc#1257447) venv-salt-minion: - Fix the issue preventing SELinux profile to be loaded on SLES 16 deployed using cloud images (bsc#1258957) - Fix the typo causing buiding EL9 bundle without binary dependencies - Backport security patches for Salt vendored tornado: * CVE-2025-67724: missing validation of supplied reason phrase (bsc#1254903) * CVE-2025-67725: fix DoS via malicious HTTP request (bsc#1254905) * CVE-2025-67726: fix HTTP header parameter parsing algorithm (bsc#1254904) - CVE-2025-62349: Add minimum_auth_version to enforce security (bsc#1254257) - CVE-2025-62348: Junos module yaml loader fix (bsc#1254256)

Exploit probability Not scored
Published March 30, 2026
Required by Not available
Last source change March 31, 2026

02 / AFFECTED SOFTWARE

Affected packages

SUSE:Multi Linux Manager Tools Beta SLE-12 golang-github-QubitProducts-exporter_exporter
SUSE:Multi Linux Manager Tools Beta SLE-12 golang-github-boynux-squid_exporter
SUSE:Multi Linux Manager Tools Beta SLE-12 golang-github-lusitaniae-apache_exporter
SUSE:Multi Linux Manager Tools Beta SLE-12 golang-github-prometheus-node_exporter
SUSE:Multi Linux Manager Tools Beta SLE-12 kiwi-desc-saltboot
SUSE:Multi Linux Manager Tools Beta SLE-12 mgr-push
SUSE:Multi Linux Manager Tools Beta SLE-12 prometheus-postgres_exporter
SUSE:Multi Linux Manager Tools Beta SLE-12 python-defusedxml
SUSE:Multi Linux Manager Tools Beta SLE-12 rhnlib
SUSE:Multi Linux Manager Tools Beta SLE-12 spacecmd
SUSE:Multi Linux Manager Tools Beta SLE-12 spacewalk-client-tools
SUSE:Multi Linux Manager Tools Beta SLE-12 supportutils-plugin-salt
SUSE:Multi Linux Manager Tools Beta SLE-12 supportutils-plugin-susemanager-client
SUSE:Multi Linux Manager Tools Beta SLE-12 uyuni-common-libs
SUSE:Multi Linux Manager Tools Beta SLE-12 uyuni-tools
SUSE:Multi Linux Manager Tools Beta SLE-12 venv-salt-minion

03 / CONNECTIONS

Connected vulnerabilities

04 / EVIDENCE

Source records

Open Source Vulnerabilities SUSE-SU-2026:1146-1

This update fixes the following issues: mgr-push: - Version 5.2.3-0 * Disable build for SLES 16 rhnlib: - Version 5.2.4-0 * Disable build for SLES 16 spacecmd: - Version 5.2.6-0 * Update translation strings spacewalk-client-tools: - Version 5.2.4-0 * Disable build for SLES 16 uyuni-common-libs: - Version 5.2.3-0 * Disable build for SLES 16 uyuni-tools: - Version 5.2.5-0 * Remove migrate command * Remove template script from mgradm: use the one in the image * Split the TFTP server into a separate container * Explicitly start proxy pods after operations (bsc#1258015) * Adjust mgrctl server filter to work with the new helm chart labels * Remove hub register command * Remove the Kubernetes install and upgrade from mgrpxy * Optimize postgres migration disk space usage (bsc#1257447) venv-salt-minion: - Fix the issue preventing SELinux profile to be loaded on SLES 16 deployed using cloud images (bsc#1258957) - Fix the typo causing buiding EL9 bundle without binary dependencies - Backport security patches for Salt vendored tornado: * CVE-2025-67724: missing validation of supplied reason phrase (bsc#1254903) * CVE-2025-67725: fix DoS via malicious HTTP request (bsc#1254905) * CVE-2025-67726: fix HTTP header parameter parsing algorithm (bsc#1254904) - CVE-2025-62349: Add minimum_auth_version to enforce security (bsc#1254257) - CVE-2025-62348: Junos module yaml loader fix (bsc#1254256)

View original source

05 / REFERENCES

Further evidence