Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
This update fixes the following issues: salt: - Update to Salt release version 3002.2 (jsc#ECO-3212) - Drop support for Python2. Obsoletes `python2-salt` package - Virt module updates * network: handle missing ipv4 netmask attribute * more network support * PCI/USB host devices passthrough support - Set distro requirement to oldest supported version in requirements/base.txt - Bring missing part of async batch implementation back - Always require python3-distro (bsc#1182293) - Remove deprecated warning that breaks minion execution when "server_id_use_crc" opts is missing - Remove msgpack < 1.0.0 from base requirements (bsc#1176293) - Msgpack support for version >= 1.0.0 (bsc#1171257) - Fix issue parsing errors in ansiblegate state module - Prevent command injection in the snapper module (bsc#1185281)
#1099976 #1171257 #1172110 #1174855 #1176293
#1177474 #1179831 #1180101 #1180818 #1181290
#1181347 #1181368 #1181550 #1181556 #1181557
#1181558 #1181559 #1181560 #1181561 #1181562
#1181563 #1181564 #1181565 #1182281 #1182293
#1182740 #1185092 #1185281 ECO-3212
Cross- CVE-2020-28243 CVE-2020-28972 CVE-2020-35662
CVE-2021-25281 CVE-2021-25282 CVE-2021-25283
CVE-2021-25284 CVE-2021-3144 CVE-2021-3148
CVE-2021-31607 CVE-2021-3197
CVSS scores:
CVE-2020-28243 (NVD) : 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVE-2020-28243 (SUSE): 8.4 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVE-2020-28972 (NVD) : 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
CVE-2020-28972 (SUSE): 7.3 CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
Get the latest Linux and open source security news straight to your inbox.