{"schema_version":"1.7.5","id":"SUSE-RU-2026:2769-1","published":"2026-07-20T09:41:45Z","modified":"2026-07-21T09:45:06.738850828Z","related":["CVE-2026-27448","CVE-2026-27459"],"upstream":["CVE-2026-27448","CVE-2026-27459"],"summary":"Recommended update 5.1.4 for Multi-Linux Manager Salt Bundle","details":"This update fixes the following issues:\n\nvenv-salt-minion:\n\n- CVE-2026-27459: large cookie value can lead to a buffer overflow (bsc#1259808)\n- CVE-2026-27448: unhandled exception can result in connection not being cancelled (bsc#1259804)\n\n- Improved shutdown reliability when the salt-master/minion is terminated\n- Fixed broken 'pkg.info_installed' after migration to salt.utils.timeutil\n- Calculate UUID grain for Xen PV guests (bsc#1255418)\n- Use non vendored tornado with Python 3.11 (bsc#1257583, bsc#1259700)\n- BDSA-2025-60810: Harden Tornado from invalid HTTP reason phrases\n- Read full URI from ldap pillar config (bsc#1254900)\n\n","affected":[{"package":{"name":"venv-salt-minion","ecosystem":"SUSE:Multi Linux Manager Tools SLE-15","purl":"pkg:rpm/suse/venv-salt-minion&distro=SUSE%20Multi%20Linux%20Manager%20Tools%20SLE-15"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"3006.0-150002.5.19.1"}]}],"ecosystem_specific":{"binaries":[{"venv-salt-minion":"3006.0-150002.5.19.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-RU-2026:2769-1.json"}},{"package":{"name":"venv-salt-minion","ecosystem":"SUSE:Multi Linux Manager Tools SLE-Micro-5","purl":"pkg:rpm/suse/venv-salt-minion&distro=SUSE%20Multi%20Linux%20Manager%20Tools%20SLE-Micro-5"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"3006.0-150002.5.19.1"}]}],"ecosystem_specific":{"binaries":[{"venv-salt-minion":"3006.0-150002.5.19.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-RU-2026:2769-1.json"}}],"references":[{"type":"ADVISORY","url":"https://www.suse.com/support/update/announcement/-2026-2769/suse-ru-20262769-1/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1254900"},{"type":"REPORT","url":"https://bugzilla.suse.com/1255418"},{"type":"REPORT","url":"https://bugzilla.suse.com/1257583"},{"type":"REPORT","url":"https://bugzilla.suse.com/1259700"},{"type":"REPORT","url":"https://bugzilla.suse.com/1259804"},{"type":"REPORT","url":"https://bugzilla.suse.com/1259808"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-27448"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-27459"}]}