SUSE-SU-2026:1523-1

Source
https://www.suse.com/support/update/announcement/2026/suse-su-20261523-1/
Import Source
https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:1523-1.json
JSON Data
https://api.osv.dev/v1/vulns/SUSE-SU-2026:1523-1
Upstream
Related
Published
2026-04-21T09:25:43Z
Modified
2026-04-22T08:16:31Z
Summary
Security update 5.1.3 for Multi-Linux Manager Salt Bundle
Details

This update fixes the following issues:

venv-salt-minion:

  • Backport security patch for Salt vendored tornado (bsc#1259554):
    • CVE-2026-31958: Add limits on multipart form data parsing
  • Add x86_64_v2 as a possible rpm package architecture
  • Make users with backslash working for salt-ssh (bsc#1254629)
  • Fix ansible.playbooks extra-vars quoting (bsc#1257831)
  • Fix virtualenv call in test helper to use proper python version
  • Fix the issue preventing SELinux profile to be loaded on SLES 16 deployed using cloud images (bsc#1258957)
  • Fix the typo causing buiding EL9 bundle without binary dependencies
References

Affected packages

SUSE:Multi Linux Manager Tools SLE-12 / venv-salt-minion

Package

Name
venv-salt-minion
Purl
pkg:rpm/suse/venv-salt-minion&distro=SUSE%20Multi%20Linux%20Manager%20Tools%20SLE-12

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
3006.0-120002.5.12.1

Ecosystem specific

{
    "binaries":  [
        {
            "venv-salt-minion":  "3006.0-120002.5.12.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:1523-1.json"