{"id":"SUSE-EL-9-CLIENT-TOOLS-2026-2255","summary":"Security update 5.0.8 for Multi-Linux Manager Salt Bundle","details":"This update fixes the following issues:\n\nvenv-salt-minion:\n\n- Security issues fixed:\n\n  - CVE-2026-31958: tornado: Fixed parsing large multipart bodies with many parts can cause a denial of service\n    (bsc#1259554)\n  - CVE-2026-27459: pyOpenSSL: Fixed issue with large cookie value that can lead to a buffer overflow (bsc#1259808)\n  - CVE-2026-27448: pyOpenSSL: Fixed unhandled exception can result in connection not being cancelled (bsc#1259804)\n\n- Other updates and bugfixes:\n\n  - Use non vendored Tornado with Python 3.11 (bsc#1257583, bsc#1259700)\n  - Hardened Tornado from invalid HTTP reason phrases\n  - Read full URI from ldap pillar config (bsc#1254900)\n  - Make users with backslash work for `salt-ssh` (bsc#1254629).\n  - Fixed `ansible.playbooks` `extra-vars` quoting (bsc#1257831),\n  - Fixed `virtualenv` call in test helper to use proper Python version.\n  - Fixed the issue preventing SELinux profile to be loaded on SLES 16\n    deployed using cloud images (bsc#1258957)\n\n","modified":"2026-07-24T18:24:26.225167094Z","published":"2026-06-03T14:19:09Z","related":["CVE-2026-27448","CVE-2026-27459","CVE-2026-31958"],"upstream":["CVE-2026-27448","CVE-2026-27459","CVE-2026-31958"],"references":[{"type":"ADVISORY","url":"https://www.suse.com/support/update/announcement//suse-el-9-client-tools-2026-2255/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1254629"},{"type":"REPORT","url":"https://bugzilla.suse.com/1254900"},{"type":"REPORT","url":"https://bugzilla.suse.com/1257583"},{"type":"REPORT","url":"https://bugzilla.suse.com/1257831"},{"type":"REPORT","url":"https://bugzilla.suse.com/1258957"},{"type":"REPORT","url":"https://bugzilla.suse.com/1259554"},{"type":"REPORT","url":"https://bugzilla.suse.com/1259700"},{"type":"REPORT","url":"https://bugzilla.suse.com/1259804"},{"type":"REPORT","url":"https://bugzilla.suse.com/1259808"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-27448"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-27459"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-31958"}],"affected":[{"package":{"name":"venv-salt-minion","ecosystem":"SUSE:Manager Client Tools for RHEL, Liberty and Clones 9-CLIENT-TOOLS","purl":"pkg:rpm/suse/venv-salt-minion&distro=SUSE%20Manager%20Client%20Tools%20for%20RHEL,%20Liberty%20and%20Clones%209-CLIENT-TOOLS"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"3006.0-1.76.1"}]}],"ecosystem_specific":{"binaries":[{"venv-salt-minion":"3006.0-1.76.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-EL-9-CLIENT-TOOLS-2026-2255.json"}}],"schema_version":"1.7.5"}