FlawAtlas
Search the atlas
SUSE-SU-2026:1149-1 Not scored

Security Beta update 5.2.0 Beta1 for Multi-Linux Manager Client Tools

This update fixes the following issues: spacecmd: - Version 5.2.6-0 * Update translation strings venv-salt-minion: - Fix the typo causing buiding EL9 bundle without binary dependencies - Backport security patches for Salt vendored tornado: * CVE-2025-67724: missing validation of supplied reason phrase (bsc#1254903) * CVE-2025-67725: fix DoS via malicious HTTP request (bsc#1254905) * CVE-2025-67726: fix HTTP header parameter parsing algorithm (bsc#1254904) - CVE-2025-62349: Add minimum_auth_version to enforce security (bsc#1254257) - CVE-2025-62348: Junos module yaml loader fix (bsc#1254256)

Exploit probability Not scored
Published March 30, 2026
Required by Not available
Last source change March 31, 2026

02 / AFFECTED SOFTWARE

Affected packages

SUSE:EL-10:Update:Products:MultiLinuxManagerToolsBeta:Update rhnlib
SUSE:EL-10:Update:Products:MultiLinuxManagerToolsBeta:Update saltbundlepy-m2crypto
SUSE:EL-10:Update:Products:MultiLinuxManagerToolsBeta:Update spacecmd
SUSE:EL-10:Update:Products:MultiLinuxManagerToolsBeta:Update spacewalk-client-tools
SUSE:EL-10:Update:Products:MultiLinuxManagerToolsBeta:Update uyuni-common-libs
SUSE:EL-10:Update:Products:MultiLinuxManagerToolsBeta:Update venv-salt-minion
SUSE:Multi Linux Manager Tools Beta EL-10 spacecmd
SUSE:Multi Linux Manager Tools Beta EL-10 venv-salt-minion

03 / CONNECTIONS

Connected vulnerabilities

04 / EVIDENCE

Source records

Open Source Vulnerabilities SUSE-SU-2026:1149-1

This update fixes the following issues: spacecmd: - Version 5.2.6-0 * Update translation strings venv-salt-minion: - Fix the typo causing buiding EL9 bundle without binary dependencies - Backport security patches for Salt vendored tornado: * CVE-2025-67724: missing validation of supplied reason phrase (bsc#1254903) * CVE-2025-67725: fix DoS via malicious HTTP request (bsc#1254905) * CVE-2025-67726: fix HTTP header parameter parsing algorithm (bsc#1254904) - CVE-2025-62349: Add minimum_auth_version to enforce security (bsc#1254257) - CVE-2025-62348: Junos module yaml loader fix (bsc#1254256)

View original source

05 / REFERENCES

Further evidence