{"schema_version":"1.7.5","id":"SUSE-SU-2026:21993-1","published":"2026-06-03T12:59:25Z","modified":"2026-06-06T18:24:20.884908560Z","related":["CVE-2026-31958"],"upstream":["CVE-2026-31958"],"summary":"Security update for salt","details":"This update for salt fixes the following issues:\n\n- Security issues fixed:\n\n  - CVE-2026-31958: tornado: Fixed parsing large multipart bodies with many parts can cause a denial of service\n    (bsc#1259554)\n\n- Other updates and bugfixes:\n  - Use non vendored Tornado with Python 3.11 (bsc#1257583, bsc#1259700)\n  - Hardened Tornado from invalid HTTP reason phrases\n  - Read full URI from ldap pillar config (bsc#1254900)\n  - Fixed testsuite failures\n  - Make users with backslash working for salt-ssh (bsc#1254629)\n  - Fixed ansible.playbooks extra-vars quoting (bsc#1257831)\n  - Fixed virtualenv call in test helper to use proper python version\n\n","references":[{"type":"ADVISORY","url":"https://www.suse.com/support/update/announcement/2026/suse-su-202621993-1/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1254629"},{"type":"REPORT","url":"https://bugzilla.suse.com/1254900"},{"type":"REPORT","url":"https://bugzilla.suse.com/1257583"},{"type":"REPORT","url":"https://bugzilla.suse.com/1257831"},{"type":"REPORT","url":"https://bugzilla.suse.com/1259554"},{"type":"REPORT","url":"https://bugzilla.suse.com/1259700"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-31958"}]}