{"schema_version":"1.7.5","id":"SUSE-SU-2026:21990-1","published":"2026-06-03T12:33:42Z","modified":"2026-06-06T18:24:19.097368628Z","related":["CVE-2026-27448","CVE-2026-27459","CVE-2026-31958"],"upstream":["CVE-2026-27448","CVE-2026-27459","CVE-2026-31958"],"summary":"Security update 5.0.8 for Multi-Linux Manager Client Tools, Salt Bundle and Salt","details":"This update fixes the following issues:\n\ngolang-github-prometheus-node_exporter:\n\n- Version 1.10.2:\n\n  * meminfo: Fix typo in Zswap metric name\n\n- Version 1.10.1:\n\n  * filesystem: Fix mount points being collected multiple\n    times\n  * filesystem: Refactor mountinfo parsing (bsc#1261810)\n  * meminfo: Add Zswap/Zswapped metrics\n\n- Version 1.10.0:\n\n  * Changes:\n\n    + mdadm: Use sysfs for RAID metrics\n    + filesystem: Add erofs in default excluded fs\n    + tcpstat: Use std lib binary.NativeEndian\n\n  * New Features:\n\n    + pcidevice: Add new collector for PCIe devices\n    + AIX: Add more metrics\n    + systemd: Add Virtualization metrics\n    + swaps: Add new collector\n\n  * Enhancements:\n\n    + wifi: Add packet received and transmitted metrics\n    + filesystem: Take super options into account for read-only\n    + pcidevice: Add additional metrics\n    + perf: Add tlb_data metrics\n\n  * Bugs fixed:\n\n    + interrupts: Fix OpenBSD interrupt device parsing\n    + diskstats: Simplify condition\n    + thermal: Sanitize darwin thermal strings\n    + filesystem: Fix Darwin collector cgo memory leak\n    + cpufreq: Fix: collector enable\n    + ethtool: Fix returning 0 for sanitized metrics\n    + netdev: Fix Darwin netdev i/o bytes metric\n    + systemd: Fix logging race\n    + filesystem: Fix duplicate Darwin CGO import\n\nsalt:\n\n- Security issues fixed:\n\n  - CVE-2026-31958: tornado: Fixed parsing large multipart bodies with many parts can cause a denial of service\n    (bsc#1259554)\n\n- Other updates and bugfixes:\n\n  - Use non vendored Tornado with Python 3.11 (bsc#1257583, bsc#1259700)\n  - Hardened Tornado from invalid HTTP reason phrases\n  - Read full URI from ldap pillar config (bsc#1254900)\n  - Fixed testsuite failures\n  - Make users with backslash working for salt-ssh (bsc#1254629)\n  - Fixed ansible.playbooks extra-vars quoting (bsc#1257831)\n  - Fixed virtualenv call in test helper to use proper python version\n\nuyuni-tools:\n\n- Version 0.1.39-0:\n\n  - mgrpxy ssh tuning should happen before crypto policies (bsc#1254619)\n  - Fixed default value for helm registry (bsc#1258927).\n  - Use static supportconfig name to avoid dynamic search\n    (bsc#1257941)\n  - Do not nest multiple tarball files and instead collect\n    all files into one tarball (bsc#1252964)\n  - Show where final tarball was generated (bsc#1259208)\n\nvenv-salt-minion:\n\n- Security issues fixed:\n\n  - CVE-2026-31958: tornado: Fixed parsing large multipart bodies with many parts can cause a denial of service\n    (bsc#1259554)\n  - CVE-2026-27459: pyOpenSSL: Fixed issue with large cookie value that can lead to a buffer overflow (bsc#1259808)\n  - CVE-2026-27448: pyOpenSSL: Fixed unhandled exception can result in connection not being cancelled (bsc#1259804)\n\n- Other updates and bugfixes:\n\n  - Use non vendored Tornado with Python 3.11 (bsc#1257583, bsc#1259700)\n  - Hardened Tornado from invalid HTTP reason phrases\n  - Read full URI from ldap pillar config (bsc#1254900)\n  - Make users with backslash work for `salt-ssh` (bsc#1254629).\n  - Fixed `ansible.playbooks` `extra-vars` quoting (bsc#1257831),\n  - Fixed `virtualenv` call in test helper to use proper Python version.\n  - Fixed the issue preventing SELinux profile to be loaded on SLES 16\n    deployed using cloud images (bsc#1258957)\n\n","references":[{"type":"ADVISORY","url":"https://www.suse.com/support/update/announcement/2026/suse-su-202621990-1/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1252964"},{"type":"REPORT","url":"https://bugzilla.suse.com/1254619"},{"type":"REPORT","url":"https://bugzilla.suse.com/1254629"},{"type":"REPORT","url":"https://bugzilla.suse.com/1254900"},{"type":"REPORT","url":"https://bugzilla.suse.com/1257583"},{"type":"REPORT","url":"https://bugzilla.suse.com/1257831"},{"type":"REPORT","url":"https://bugzilla.suse.com/1257941"},{"type":"REPORT","url":"https://bugzilla.suse.com/1258927"},{"type":"REPORT","url":"https://bugzilla.suse.com/1258957"},{"type":"REPORT","url":"https://bugzilla.suse.com/1259208"},{"type":"REPORT","url":"https://bugzilla.suse.com/1259554"},{"type":"REPORT","url":"https://bugzilla.suse.com/1259700"},{"type":"REPORT","url":"https://bugzilla.suse.com/1259804"},{"type":"REPORT","url":"https://bugzilla.suse.com/1259808"},{"type":"REPORT","url":"https://bugzilla.suse.com/1261810"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-27448"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-27459"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-31958"}]}