FlawAtlas
Search the atlas
SUSE-SU-2026:21990-1 Not scored

Security update 5.0.8 for Multi-Linux Manager Client Tools, Salt Bundle and Salt

This update fixes the following issues: golang-github-prometheus-node_exporter: - Version 1.10.2: * meminfo: Fix typo in Zswap metric name - Version 1.10.1: * filesystem: Fix mount points being collected multiple times * filesystem: Refactor mountinfo parsing (bsc#1261810) * meminfo: Add Zswap/Zswapped metrics - Version 1.10.0: * Changes: + mdadm: Use sysfs for RAID metrics + filesystem: Add erofs in default excluded fs + tcpstat: Use std lib binary.NativeEndian * New Features: + pcidevice: Add new collector for PCIe devices + AIX: Add more metrics + systemd: Add Virtualization metrics + swaps: Add new collector * Enhancements: + wifi: Add packet received and transmitted metrics + filesystem: Take super options into account for read-only + pcidevice: Add additional metrics + perf: Add tlb_data metrics * Bugs fixed: + interrupts: Fix OpenBSD interrupt device parsing + diskstats: Simplify condition + thermal: Sanitize darwin thermal strings + filesystem: Fix Darwin collector cgo memory leak + cpufreq: Fix: collector enable + ethtool: Fix returning 0 for sanitized metrics + netdev: Fix Darwin netdev i/o bytes metric + systemd: Fix logging race + filesystem: Fix duplicate Darwin CGO import salt: - Security issues fixed: - CVE-2026-31958: tornado: Fixed parsing large multipart bodies with many parts can cause a denial of service (bsc#1259554) - Other updates and bugfixes: - Use non vendored Tornado with Python 3.11 (bsc#1257583, bsc#1259700) - Hardened Tornado from invalid HTTP reason phrases - Read full URI from ldap pillar config (bsc#1254900) - Fixed testsuite failures - Make users with backslash working for salt-ssh (bsc#1254629) - Fixed ansible.playbooks extra-vars quoting (bsc#1257831) - Fixed virtualenv call in test helper to use proper python version uyuni-tools: - Version 0.1.39-0: - mgrpxy ssh tuning should happen before crypto policies (bsc#1254619) - Fixed default value for helm registry (bsc#1258927). - Use static supportconfig name to avoid dynamic search (bsc#1257941) - Do not nest multiple tarball files and instead collect all files into one tarball (bsc#1252964) - Show where final tarball was generated (bsc#1259208) venv-salt-minion: - Security issues fixed: - CVE-2026-31958: tornado: Fixed parsing large multipart bodies with many parts can cause a denial of service (bsc#1259554) - CVE-2026-27459: pyOpenSSL: Fixed issue with large cookie value that can lead to a buffer overflow (bsc#1259808) - CVE-2026-27448: pyOpenSSL: Fixed unhandled exception can result in connection not being cancelled (bsc#1259804) - Other updates and bugfixes: - Use non vendored Tornado with Python 3.11 (bsc#1257583, bsc#1259700) - Hardened Tornado from invalid HTTP reason phrases - Read full URI from ldap pillar config (bsc#1254900) - Make users with backslash work for `salt-ssh` (bsc#1254629). - Fixed `ansible.playbooks` `extra-vars` quoting (bsc#1257831), - Fixed `virtualenv` call in test helper to use proper Python version. - Fixed the issue preventing SELinux profile to be loaded on SLES 16 deployed using cloud images (bsc#1258957)

Exploit probability Not scored
Published June 3, 2026
Required by Not available
Last source change June 6, 2026

03 / CONNECTIONS

Connected vulnerabilities

04 / EVIDENCE

Source records

Open Source Vulnerabilities SUSE-SU-2026:21990-1

This update fixes the following issues: golang-github-prometheus-node_exporter: - Version 1.10.2: * meminfo: Fix typo in Zswap metric name - Version 1.10.1: * filesystem: Fix mount points being collected multiple times * filesystem: Refactor mountinfo parsing (bsc#1261810) * meminfo: Add Zswap/Zswapped metrics - Version 1.10.0: * Changes: + mdadm: Use sysfs for RAID metrics + filesystem: Add erofs in default excluded fs + tcpstat: Use std lib binary.NativeEndian * New Features: + pcidevice: Add new collector for PCIe devices + AIX: Add more metrics + systemd: Add Virtualization metrics + swaps: Add new collector * Enhancements: + wifi: Add packet received and transmitted metrics + filesystem: Take super options into account for read-only + pcidevice: Add additional metrics + perf: Add tlb_data metrics * Bugs fixed: + interrupts: Fix OpenBSD interrupt device parsing + diskstats: Simplify condition + thermal: Sanitize darwin thermal strings + filesystem: Fix Darwin collector cgo memory leak + cpufreq: Fix: collector enable + ethtool: Fix returning 0 for sanitized metrics + netdev: Fix Darwin netdev i/o bytes metric + systemd: Fix logging race + filesystem: Fix duplicate Darwin CGO import salt: - Security issues fixed: - CVE-2026-31958: tornado: Fixed parsing large multipart bodies with many parts can cause a denial of service (bsc#1259554) - Other updates and bugfixes: - Use non vendored Tornado with Python 3.11 (bsc#1257583, bsc#1259700) - Hardened Tornado from invalid HTTP reason phrases - Read full URI from ldap pillar config (bsc#1254900) - Fixed testsuite failures - Make users with backslash working for salt-ssh (bsc#1254629) - Fixed ansible.playbooks extra-vars quoting (bsc#1257831) - Fixed virtualenv call in test helper to use proper python version uyuni-tools: - Version 0.1.39-0: - mgrpxy ssh tuning should happen before crypto policies (bsc#1254619) - Fixed default value for helm registry (bsc#1258927). - Use static supportconfig name to avoid dynamic search (bsc#1257941) - Do not nest multiple tarball files and instead collect all files into one tarball (bsc#1252964) - Show where final tarball was generated (bsc#1259208) venv-salt-minion: - Security issues fixed: - CVE-2026-31958: tornado: Fixed parsing large multipart bodies with many parts can cause a denial of service (bsc#1259554) - CVE-2026-27459: pyOpenSSL: Fixed issue with large cookie value that can lead to a buffer overflow (bsc#1259808) - CVE-2026-27448: pyOpenSSL: Fixed unhandled exception can result in connection not being cancelled (bsc#1259804) - Other updates and bugfixes: - Use non vendored Tornado with Python 3.11 (bsc#1257583, bsc#1259700) - Hardened Tornado from invalid HTTP reason phrases - Read full URI from ldap pillar config (bsc#1254900) - Make users with backslash work for `salt-ssh` (bsc#1254629). - Fixed `ansible.playbooks` `extra-vars` quoting (bsc#1257831), - Fixed `virtualenv` call in test helper to use proper Python version. - Fixed the issue preventing SELinux profile to be loaded on SLES 16 deployed using cloud images (bsc#1258957)

View original source

05 / REFERENCES

Further evidence