{"schema_version":"1.7.5","id":"SUSE-SU-2026:2242-1","published":"2026-06-03T14:05:41Z","modified":"2026-06-04T09:00:07.801292354Z","related":["CVE-2026-27448","CVE-2026-27459","CVE-2026-31958"],"upstream":["CVE-2026-27448","CVE-2026-27459","CVE-2026-31958"],"summary":"Security update 5.0.8 for Multi-Linux Manager Salt Bundle","details":"This update fixes the following issues:\n\nvenv-salt-minion:\n\n- Security issues fixed:\n\n  - CVE-2026-31958: tornado: Fixed parsing large multipart bodies with many parts can cause a denial of service\n    (bsc#1259554)\n  - CVE-2026-27459: pyOpenSSL: Fixed issue with large cookie value that can lead to a buffer overflow (bsc#1259808)\n  - CVE-2026-27448: pyOpenSSL: Fixed unhandled exception can result in connection not being cancelled (bsc#1259804)\n\n- Other updates and bugfixes:\n\n  - Use non vendored Tornado with Python 3.11 (bsc#1257583, bsc#1259700)\n  - Hardened Tornado from invalid HTTP reason phrases\n  - Read full URI from ldap pillar config (bsc#1254900)\n  - Make users with backslash work for `salt-ssh` (bsc#1254629).\n  - Fixed `ansible.playbooks` `extra-vars` quoting (bsc#1257831),\n  - Fixed `virtualenv` call in test helper to use proper Python version.\n  - Fixed the issue preventing SELinux profile to be loaded on SLES 16\n    deployed using cloud images (bsc#1258957)\n\n","references":[{"type":"ADVISORY","url":"https://www.suse.com/support/update/announcement/2026/suse-su-20262242-1/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1254629"},{"type":"REPORT","url":"https://bugzilla.suse.com/1254900"},{"type":"REPORT","url":"https://bugzilla.suse.com/1257583"},{"type":"REPORT","url":"https://bugzilla.suse.com/1257831"},{"type":"REPORT","url":"https://bugzilla.suse.com/1258957"},{"type":"REPORT","url":"https://bugzilla.suse.com/1259554"},{"type":"REPORT","url":"https://bugzilla.suse.com/1259700"},{"type":"REPORT","url":"https://bugzilla.suse.com/1259804"},{"type":"REPORT","url":"https://bugzilla.suse.com/1259808"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-27448"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-27459"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-31958"}]}