Alerts This Week
Warning Icon 1 764
Alerts This Week
Warning Icon 1 764

SUSE: Severe Denial of Service Vulnerability in Multi-Linux Tools Alert

suse
Calendar Grey July 23, 2025
Dist Suse Esm H88
The 5.0.5 security patch addresses severe flaws in Multi-Linux Admin Client Utilities for SUSE, with detailed patch notes provided.
* bsc#1236621 * bsc#1236877 * bsc#1238849 * bsc#1238929 * bsc#1240626

Summary

## This update fixes the following issues: salt: * Security issues fixed: * CVE-2024-38822: Fixed Minion token validation (bsc#1244561) * CVE-2024-38823: Fixed server vulnerability to replay attacks when not using a TLS encrypted transport (bsc#1244564) * CVE-2024-38824: Fixed directory traversal vulnerability in recv_file method (bsc#1244565) * CVE-2024-38825: Fixed salt.auth.pki module authentication issue (bsc#1244566) * CVE-2025-22240: Fixed arbitrary directory creation or file deletion with GitFS (bsc#1244567) * CVE-2025-22236: Fixed Minion event bus authorization bypass (bsc#1244568) * CVE-2025-22241: Fixed the use of un-validated input in the VirtKey class (bsc#1244570) * CVE-2025-22237: Fixed exploitation of the 'on demand' pillar functionality (bsc#1244571)

References

* bsc#1236621

* bsc#1236877

* bsc#1238849

* bsc#1238929

* bsc#1240626

* bsc#1240698

* bsc#1242174

* bsc#1243105

* bsc#1243268

* bsc#1243274

* bsc#1243297

* bsc#1243802

* bsc#1244561

* bsc#1244564

* bsc#1244565

* bsc#1244566

* bsc#1244567

* bsc#1244568

* bsc#1244570

* bsc#1244571

* bsc#1244572

* bsc#1244574

* bsc#1244575

* jsc#ECO-3319

* jsc#MSQA-993

Cross-

* CVE-2024-38822

* CVE-2024-38823

* CVE-2024-38824

* CVE-2024-38825

* CVE-2025-22236

* CVE-2025-22237

* CVE-2025-22238

* CVE-2025-22239

* CVE-2025-22240

* CVE-2025-22241

* CVE-2025-22242

* CVE-2025-47287

CVSS scores:

* CVE-2024-38822 ( SUSE ): 5.1

CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N

* CVE-2024-38822 ( SUSE ): 2.7 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:N

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-202507:15303-1
Release Date: 2025-07-23T12:41:47Z
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here