Alerts This Week
Warning Icon 1 692
Alerts This Week
Warning Icon 1 692

SUSE: Salt Important Security Update CVE-2024-38822 and Others 2025:02534-1

suse
Calendar Grey July 28, 2025
Dist Suse Esm H88
Important security fix for SUSE Salt tackles several concerns including denial-of-service vulnerabilities. Update your systems immediately!
* bsc#1236621 * bsc#1243268 * bsc#1244561 * bsc#1244564 * bsc#1244565

Summary

## This update for salt fixes the following issues: * Security issues fixed: * CVE-2024-38822: Fixed Minion token validation (bsc#1244561) * CVE-2024-38823: Fixed server vulnerability to replay attacks when not using a TLS encrypted transport (bsc#1244564) * CVE-2024-38824: Fixed directory traversal vulnerability in recv_file method (bsc#1244565) * CVE-2024-38825: Fixed salt.auth.pki module authentication issue (bsc#1244566) * CVE-2025-22240: Fixed arbitrary directory creation or file deletion with GitFS (bsc#1244567) * CVE-2025-22236: Fixed Minion event bus authorization bypass (bsc#1244568) * CVE-2025-22241: Fixed the use of un-validated input in the VirtKey class (bsc#1244570) * CVE-2025-22237: Fixed exploitation of the 'on demand' pillar functionality (bsc#1244571)

References

* bsc#1236621

* bsc#1243268

* bsc#1244561

* bsc#1244564

* bsc#1244565

* bsc#1244566

* bsc#1244567

* bsc#1244568

* bsc#1244570

* bsc#1244571

* bsc#1244572

* bsc#1244574

* bsc#1244575

Cross-

* CVE-2024-38822

* CVE-2024-38823

* CVE-2024-38824

* CVE-2024-38825

* CVE-2025-22236

* CVE-2025-22237

* CVE-2025-22238

* CVE-2025-22239

* CVE-2025-22240

* CVE-2025-22241

* CVE-2025-22242

* CVE-2025-47287

CVSS scores:

* CVE-2024-38822 ( SUSE ): 5.1

CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N

* CVE-2024-38822 ( SUSE ): 2.7 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:N

* CVE-2024-38822 ( NVD ): 2.7 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:N

* CVE-2024-38823 ( SUSE ): 8.2

CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2025:02534-1
Release Date: 2025-07-28T12:45:33Z
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here