This update for salt fixes the following issue:
Security issues fixed:
* CVE-2026-31958: python-tornado: parsing large multipart bodies with many
parts can cause a denial of service (bsc#1259554).
Other updates and bugfixes:
* Use non vendored Tornado with Python 3.11 (bsc#1257583, bsc#1259700)
* Harden Tornado from invalid HTTP reason phrases
* Read full URI from ldap pillar config (bsc#1254900)
* Make users with backslash work for `salt-ssh` (bsc#1254629).
* Fixed `ansible.playbooks` `extra-vars` quoting (bsc#1257831),
* Fixed `virtualenv` call in test helper to use proper Python version.
## Special Instructions and Notes:
## Patch Instructions:
To install this SUSE update use the SUSE recommended installation methods like
YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
* openSUSE Leap 15.4
zypper in -t patch SUSE-2026-2252=1
* SUSE Linux Enterprise Micro for Rancher 5.3
zypper in -t patch SUSE-SLE-Micro-5.3-2026-2252=1
* SUSE Linux Enterprise Micro 5.3
zypper in -t patch SUSE-SLE-Micro-5.3-2026-2252=1
* SUSE Linux Enterprise Server 15 SP4 LTSS
zypper in -t patch SUSE-SLE-Product-SLES-15-SP4-LTSS-2026-2252=1
* SUSE Linux Enterprise Micro for Rancher 5.4
zypper in -t patch SUSE-SLE-Micro-5.4-2026-2252=1
* SUSE Linux Enterprise Micro 5.4
zypper in -t patch SUSE-SLE-Micro-5.4-2026-2252=1
* SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4
zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-ESPOS-2026-2252=1
* SUSE Linux Enterprise High Performance Computing LTSS 15 SP4
zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-LTSS-2026-2252=1
* SUSE Linux Enterprise Server for...
Read the Full Advisory* openSUSE Leap 15.4 (aarch64 ppc64le s390x x86_64 i586)
* python3-salt-testsuite-3006.0-150400.8.101.1
* salt-master-3006.0-150400.8.101.1
* salt-transactional-update-3006.0-150400.8.101.1
* salt-api-3006.0-150400.8.101.1
* python3-salt-3006.0-150400.8.101.1
* salt-doc-3006.0-150400.8.101.1
* salt-standalone-formulas-configuration-3006.0-150400.8.101.1
* salt-cloud-3006.0-150400.8.101.1
* python311-salt-testsuite-3006.0-150400.8.101.1
* salt-syndic-3006.0-150400.8.101.1
* python311-salt-3006.0-150400.8.101.1
* salt-ssh-3006.0-150400.8.101.1
* salt-proxy-3006.0-150400.8.101.1
* salt-minion-3006.0-150400.8.101.1
* salt-3006.0-150400.8.101.1
* openSUSE Leap 15.4 (noarch)
* salt-fish-completion-3006.0-150400.8.101.1
* salt-bash-completion-3006.0-150400.8.101.1
* salt-zsh-completion-3006.0-150400.8.101.1
* SUSE Linux Enterprise Micro for Rancher 5.3 (aarch64 s390x x86_64)
* salt-minion-3006.0-150400.8.101.1
* salt-3006.0-150400.8.101.1
* salt-transactional-update-3006.0-150400.8.101.1
*...
Read the Full Advisory* bsc#1254629
* bsc#1254900
* bsc#1257583
* bsc#1257831
* bsc#1259554
* bsc#1259700
* jsc#MSQA-1052
## References:
* https://www.suse.com/security/cve/CVE-2026-31958.html
* https://bugzilla.suse.com/show_bug.cgi?id=1254629
* https://bugzilla.suse.com/show_bug.cgi?id=1254900
* https://bugzilla.suse.com/show_bug.cgi?id=1257583
* https://bugzilla.suse.com/show_bug.cgi?id=1257831
* https://bugzilla.suse.com/show_bug.cgi?id=1259554
* https://bugzilla.suse.com/show_bug.cgi?id=1259700
* https://jira.suse.com/browse/MSQA-1052
Get the latest Linux and open source security news straight to your inbox.