SUSE-EL-9-CLIENT-TOOLS-2026-1026

Published: 25 Mar 2026, 10:15
Last modified:24 Jul 2026, 18:24

Vulnerability Summary

Overall Risk (default)
minimal
0/100
CVSS Score
No data
EPSS Score
No data
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

25 Mar 2026, 10:15
Published
Vulnerability first disclosed
24 Jul 2026, 18:24
Last Modified
Vulnerability information updated

Description

Security update 5.0.7 for Multi-Linux Manager Salt Bundle This update fixes the following issues: venv-salt-minion: - Security issues fixed: * CVE-2025-67724: fixed missing validation of supplied reason phrase (bsc#1254903) * CVE-2025-67725: fixed DoS via malicious HTTP request (bsc#1254905) * CVE-2025-67726: fixed HTTP header parameter parsing algorithm (bsc#1254904) * CVE-2025-62349: Added minimum_auth_version to enforce security (bsc#1254257) * CVE-2025-62348: Fixed Junos module yaml loader (bsc#1254256) * CVE-2025-13836: Set a safe limit to http.client response read (bsc#1254400) - Fixed KeyError in postgres module with PostgreSQL 17 (bsc#1254325) - Use internal deb classes instead of external aptsource lib - Improved performance of wheel key.finger call (bsc#1240532) - Improved performance of utils.find_json function (bsc#1246130) - Extended warn_until period to 2027

Affected Systems

  • susevenv-salt-minion&distro=SUSE Manager Client Tools for RHEL, Liberty and Clones 9-CLIENT-TOOLS

    < 3006.0-1.67.1

References (16)