SUSE-SU-2025:21218-1
Vulnerability Summary
Timeline
Description
Security update for salt This update for salt fixes the following issues: salt: - Security issues fixed: - CVE-2025-62349: Added minimum_auth_version to enforce security (bsc#1254257) - CVE-2025-62348: Fixed Junos module yaml loader (bsc#1254256) - Backport security fixes for vendored tornado * BDSA-2024-3438 * BDSA-2024-3439 * BDSA-2024-9026 - Other changes and bugs fixed: - Added `minion_legacy_req_warnings` option to avoid noisy warnings - Fixed TLS and x509 modules for OSes with older cryptography module - Fixed Salt for Python > 3.11 (bsc#1252285) (bsc#1252244) * Use external tornado on Python > 3.11 * Make tls and x509 to use python-cryptography * Remove usage of spwd - Fixed payload signature verification on Tumbleweed (bsc#1251776) - Fixed broken symlink on migration to Leap 16.0 (bsc#1250755) - Fixed known_hosts error on gitfs (bsc#1250520) (bsc#1227207) - Fixed functional.states.test_user for SLES 16 and Micro systems - Fixed the tests failing on AlmaLinux 10 and other clones - Improved SL Micro 6.2 detection with grains - Require Python dependencies only for used Python version - Reverted requirement of M2Crypto >= 0.44.0 for SUSE Family distros - Set python-CherryPy as required for python-salt-testsuite
Affected Systems
- suse•salt&distro=SUSE Linux Micro 6.1
< 3006.0-slfo.1.1_5.1
References (9)
- https://www.suse.com/support/update/announcement/2025/suse-su-202521218-1/
- https://bugzilla.suse.com/1227207
- https://bugzilla.suse.com/1250520
- https://bugzilla.suse.com/1250755
- https://bugzilla.suse.com/1251776
- https://bugzilla.suse.com/1252244
- https://bugzilla.suse.com/1252285
- https://www.suse.com/security/cve/CVE-2025-62348
- https://www.suse.com/security/cve/CVE-2025-62349