This update for salt fixes the following issues:
* Security issues fixed:
* CVE-2024-38822: Fixed Minion token validation (bsc#1244561)
* CVE-2024-38823: Fixed server vulnerability to replay attacks when not using
a TLS encrypted transport (bsc#1244564)
* CVE-2024-38824: Fixed directory traversal vulnerability in recv_file method
(bsc#1244565)
* CVE-2024-38825: Fixed salt.auth.pki module authentication issue
(bsc#1244566)
* CVE-2025-22240: Fixed arbitrary directory creation or file deletion with
GitFS (bsc#1244567)
* CVE-2025-22236: Fixed Minion event bus authorization bypass (bsc#1244568)
* CVE-2025-22241: Fixed the use of un-validated input in the VirtKey class
(bsc#1244570)
* CVE-2025-22237: Fixed exploitation of the 'on demand' pillar functionality
(bsc#1244571)
* CVE-2025-22238: Fixed the master's default cache vulnerability to a
directory traversal attack (bsc#1244572)
* CVE-2025-22239: Fixed the arbitrary event injection on...
Read the Full Advisory## Patch Instructions:
To install this SUSE update use the SUSE recommended installation methods like
YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
* openSUSE Leap 15.4
zypper in -t patch SUSE-2025-2500=1
* SUSE Linux Enterprise Micro for Rancher 5.3
zypper in -t patch SUSE-SLE-Micro-5.3-2025-2500=1
* SUSE Linux Enterprise Micro 5.3
zypper in -t patch SUSE-SLE-Micro-5.3-2025-2500=1
* SUSE Linux Enterprise Micro for Rancher 5.4
zypper in -t patch SUSE-SLE-Micro-5.4-2025-2500=1
* SUSE Linux Enterprise Micro 5.4
zypper in -t patch SUSE-SLE-Micro-5.4-2025-2500=1
* SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4
zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-ESPOS-2025-2500=1
* SUSE Linux Enterprise High Performance Computing LTSS 15 SP4
zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-LTSS-2025-2500=1
* SUSE Linux Enterprise Server 15 SP4 LTSS
zypper in -t patch SUSE-SLE-Product-SLES-15-SP4-LTSS-2025-2500=1
* SUSE Linux Enterprise Server for...
Read the Full Advisory* openSUSE Leap 15.4 (aarch64 ppc64le s390x x86_64 i586)
* salt-syndic-3006.0-150400.8.80.1
* salt-doc-3006.0-150400.8.80.1
* python311-salt-testsuite-3006.0-150400.8.80.1
* salt-ssh-3006.0-150400.8.80.1
* salt-standalone-formulas-configuration-3006.0-150400.8.80.1
* salt-transactional-update-3006.0-150400.8.80.1
* salt-3006.0-150400.8.80.1
* salt-api-3006.0-150400.8.80.1
* python3-salt-3006.0-150400.8.80.1
* salt-master-3006.0-150400.8.80.1
* salt-proxy-3006.0-150400.8.80.1
* python3-salt-testsuite-3006.0-150400.8.80.1
* salt-cloud-3006.0-150400.8.80.1
* salt-minion-3006.0-150400.8.80.1
* python311-salt-3006.0-150400.8.80.1
* openSUSE Leap 15.4 (noarch)
* salt-zsh-completion-3006.0-150400.8.80.1
* salt-fish-completion-3006.0-150400.8.80.1
* salt-bash-completion-3006.0-150400.8.80.1
* SUSE Linux Enterprise Micro for Rancher 5.3 (aarch64 s390x x86_64)
* salt-transactional-update-3006.0-150400.8.80.1
* salt-minion-3006.0-150400.8.80.1
* salt-3006.0-150400.8.80.1
* python3-salt-3006.0-150400.8.80.1
* SUSE Linux...
Read the Full Advisory* bsc#1236621
* bsc#1243268
* bsc#1244561
* bsc#1244564
* bsc#1244565
* bsc#1244566
* bsc#1244567
* bsc#1244568
* bsc#1244570
* bsc#1244571
* bsc#1244572
* bsc#1244574
* bsc#1244575
* jsc#MSQA-993
## References:
* https://www.suse.com/security/cve/CVE-2024-38822.html
* https://www.suse.com/security/cve/CVE-2024-38823.html
* https://www.suse.com/security/cve/CVE-2024-38824.html
* https://www.suse.com/security/cve/CVE-2024-38825.html
* https://www.suse.com/security/cve/CVE-2025-22236.html
* https://www.suse.com/security/cve/CVE-2025-22237.html
* https://www.suse.com/security/cve/CVE-2025-22238.html
* https://www.suse.com/security/cve/CVE-2025-22239.html
* https://www.suse.com/security/cve/CVE-2025-22240.html
* https://www.suse.com/security/cve/CVE-2025-22241.html
* https://www.suse.com/security/cve/CVE-2025-22242.html
* https://www.suse.com/security/cve/CVE-2025-47287.html
* https://bugzilla.suse.com/show_bug.cgi?id=1236621
* https://bugzilla.suse.com/show_bug.cgi?id=1243268
*...
Read the Full AdvisoryGet the latest Linux and open source security news straight to your inbox.