This update for salt fixes the following issues:
* Security issues fixed:
* CVE-2024-38822: Fixed Minion token validation (bsc#1244561)
* CVE-2024-38823: Fixed server vulnerability to replay attacks when not using
a TLS encrypted transport (bsc#1244564)
* CVE-2024-38824: Fixed directory traversal vulnerability in recv_file method
(bsc#1244565)
* CVE-2024-38825: Fixed salt.auth.pki module authentication issue
(bsc#1244566)
* CVE-2025-22240: Fixed arbitrary directory creation or file deletion with
GitFS (bsc#1244567)
* CVE-2025-22236: Fixed Minion event bus authorization bypass (bsc#1244568)
* CVE-2025-22241: Fixed the use of un-validated input in the VirtKey class
(bsc#1244570)
* CVE-2025-22237: Fixed exploitation of the 'on demand' pillar functionality
(bsc#1244571)
* CVE-2025-22238: Fixed the master's default cache vulnerability to a
directory traversal attack (bsc#1244572)
* CVE-2025-22239: Fixed the arbitrary event injection on...
Read the Full Advisory## Patch Instructions:
To install this SUSE update use the SUSE recommended installation methods like
YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
* openSUSE Leap 15.6
zypper in -t patch openSUSE-SLE-15.6-2025-2501=1
* SUSE Linux Enterprise Micro 5.5
zypper in -t patch SUSE-SLE-Micro-5.5-2025-2501=1
* Basesystem Module 15-SP6
zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP6-2025-2501=1
* Server Applications Module 15-SP6
zypper in -t patch SUSE-SLE-Module-Server-Applications-15-SP6-2025-2501=1
* Transactional Server Module 15-SP6
zypper in -t patch SUSE-SLE-Module-Transactional-Server-15-SP6-2025-2501=1
* SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5
zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-ESPOS-2025-2501=1
* SUSE Linux Enterprise High Performance Computing LTSS 15 SP5
zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-LTSS-2025-2501=1
* SUSE Linux Enterprise Server 15 SP5 LTSS
zypper in -t patch...
Read the Full Advisory* openSUSE Leap 15.6 (aarch64 ppc64le s390x x86_64)
* salt-ssh-3006.0-150500.4.55.1
* salt-proxy-3006.0-150500.4.55.1
* salt-doc-3006.0-150500.4.55.1
* salt-minion-3006.0-150500.4.55.1
* salt-syndic-3006.0-150500.4.55.1
* salt-transactional-update-3006.0-150500.4.55.1
* python3-salt-testsuite-3006.0-150500.4.55.1
* salt-master-3006.0-150500.4.55.1
* salt-3006.0-150500.4.55.1
* salt-standalone-formulas-configuration-3006.0-150500.4.55.1
* python3-salt-3006.0-150500.4.55.1
* salt-api-3006.0-150500.4.55.1
* salt-cloud-3006.0-150500.4.55.1
* openSUSE Leap 15.6 (noarch)
* salt-zsh-completion-3006.0-150500.4.55.1
* salt-bash-completion-3006.0-150500.4.55.1
* salt-fish-completion-3006.0-150500.4.55.1
* SUSE Linux Enterprise Micro 5.5 (aarch64 ppc64le s390x x86_64)
* salt-minion-3006.0-150500.4.55.1
* salt-transactional-update-3006.0-150500.4.55.1
* salt-3006.0-150500.4.55.1
* python3-salt-3006.0-150500.4.55.1
* Basesystem Module 15-SP6 (aarch64 ppc64le s390x x86_64)
* salt-minion-3006.0-150500.4.55.1
*...
Read the Full Advisory* bsc#1236621
* bsc#1243268
* bsc#1244561
* bsc#1244564
* bsc#1244565
* bsc#1244566
* bsc#1244567
* bsc#1244568
* bsc#1244570
* bsc#1244571
* bsc#1244572
* bsc#1244574
* bsc#1244575
* jsc#MSQA-993
## References:
* https://www.suse.com/security/cve/CVE-2024-38822.html
* https://www.suse.com/security/cve/CVE-2024-38823.html
* https://www.suse.com/security/cve/CVE-2024-38824.html
* https://www.suse.com/security/cve/CVE-2024-38825.html
* https://www.suse.com/security/cve/CVE-2025-22236.html
* https://www.suse.com/security/cve/CVE-2025-22237.html
* https://www.suse.com/security/cve/CVE-2025-22238.html
* https://www.suse.com/security/cve/CVE-2025-22239.html
* https://www.suse.com/security/cve/CVE-2025-22240.html
* https://www.suse.com/security/cve/CVE-2025-22241.html
* https://www.suse.com/security/cve/CVE-2025-22242.html
* https://www.suse.com/security/cve/CVE-2025-47287.html
* https://bugzilla.suse.com/show_bug.cgi?id=1236621
* https://bugzilla.suse.com/show_bug.cgi?id=1243268
*...
Read the Full AdvisoryGet the latest Linux and open source security news straight to your inbox.