openSUSE-SU-2026:20000-1

See a problem?
Import Source
https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2026:20000-1.json
JSON Data
https://api.osv.dev/v1/vulns/openSUSE-SU-2026:20000-1
Upstream
CVE (2)
  • CVE-2025-62348
  • CVE-2025-62349
Related
Published
2025-12-23T09:11:50Z
Modified
2026-03-23T04:54:40Z
Summary
Security update for salt
Details

This update for salt fixes the following issues:

Changes in salt:

  • Add minimum_auth_version to enforce security (CVE-2025-62349)
  • Backport security fixes for vendored tornado
    • BDSA-2024-3438
    • BDSA-2024-3439
    • BDSA-2024-9026
  • Junos module yaml loader fix (CVE-2025-62348)
  • Require Python dependencies only for used Python version
  • Fix TLS and x509 modules for OSes with older cryptography module
  • Fix Salt for Python > 3.11 (bsc#1252285, bsc#1252244)
  • Fix payload signature verification on Tumbleweed (bsc#1251776)
  • Fix broken symlink on migration to Leap 16.0 (bsc#1250755)
  • Use versioned python interpreter for salt-ssh
  • Fix known_hosts error on gitfs (bsc#1250520, bsc#1227207)
  • Revert require M2Crypto >= 0.44.0 for SUSE Family distros
  • Improve SL Micro 6.2 detection with grains
  • Fix the tests failing on AlmaLinux 10 and other clones
References

Affected packages

openSUSE:Leap 16.0 / salt

Package

Name
salt
Purl
pkg:rpm/opensuse/salt&distro=openSUSE%20Leap%2016.0

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
3006.0-160000.3.1

Ecosystem specific

{
    "binaries":  [
        {
            "python313-salt":  "3006.0-160000.3.1",
            "python313-salt-testsuite":  "3006.0-160000.3.1",
            "salt":  "3006.0-160000.3.1",
            "salt-api":  "3006.0-160000.3.1",
            "salt-bash-completion":  "3006.0-160000.3.1",
            "salt-cloud":  "3006.0-160000.3.1",
            "salt-doc":  "3006.0-160000.3.1",
            "salt-fish-completion":  "3006.0-160000.3.1",
            "salt-master":  "3006.0-160000.3.1",
            "salt-minion":  "3006.0-160000.3.1",
            "salt-proxy":  "3006.0-160000.3.1",
            "salt-ssh":  "3006.0-160000.3.1",
            "salt-standalone-formulas-configuration":  "3006.0-160000.3.1",
            "salt-syndic":  "3006.0-160000.3.1",
            "salt-transactional-update":  "3006.0-160000.3.1",
            "salt-zsh-completion":  "3006.0-160000.3.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2026:20000-1.json"

openSUSE:Leap 16.0 / salt-test

Package

Name
salt-test
Purl
pkg:rpm/opensuse/salt-test&distro=openSUSE%20Leap%2016.0

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
3006.0-160000.3.1

Ecosystem specific

{
    "binaries":  [
        {
            "python313-salt":  "3006.0-160000.3.1",
            "python313-salt-testsuite":  "3006.0-160000.3.1",
            "salt":  "3006.0-160000.3.1",
            "salt-api":  "3006.0-160000.3.1",
            "salt-bash-completion":  "3006.0-160000.3.1",
            "salt-cloud":  "3006.0-160000.3.1",
            "salt-doc":  "3006.0-160000.3.1",
            "salt-fish-completion":  "3006.0-160000.3.1",
            "salt-master":  "3006.0-160000.3.1",
            "salt-minion":  "3006.0-160000.3.1",
            "salt-proxy":  "3006.0-160000.3.1",
            "salt-ssh":  "3006.0-160000.3.1",
            "salt-standalone-formulas-configuration":  "3006.0-160000.3.1",
            "salt-syndic":  "3006.0-160000.3.1",
            "salt-transactional-update":  "3006.0-160000.3.1",
            "salt-zsh-completion":  "3006.0-160000.3.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2026:20000-1.json"