Alerts This Week
Warning Icon 1 764
Alerts This Week
Warning Icon 1 764

SUSE Linux Micro 6.0 Salt Important DoS Fixes SUSE-SU-2026-20820-1

suse
Calendar Grey March 25, 2026
Dist Suse Esm H88
SUSE releases important security update for salt addressing multiple issues and enhancing performance for better security.
An update that solves four vulnerabilities and has three fixes can now be installed.

Summary

## This update for salt fixes the following issues: * Security issues fixed: * CVE-2025-67724: Fixed missing validation of supplied reason phrase (bsc#1254903) * CVE-2025-67725: Fixed DoS via malicious HTTP request (bsc#1254905) * CVE-2025-67726: Fixed HTTP header parameter parsing algorithm (bsc#1254904) * CVE-2025-13836: Set a safe limit to http.client response read (bsc#1254400) * Fixed KeyError in postgres module with PostgreSQL 17 (bsc#1254325) * Use internal deb classes instead of external aptsource lib * Improved performance of wheel key.finger call (bsc#1240532) * Improved performance of utils.find_json function (bsc#1246130) * Extended warn_until period to 2027

References

* bsc#1240532

* bsc#1246130

* bsc#1254325

* bsc#1254400

* bsc#1254903

* bsc#1254904

* bsc#1254905

Cross-

* CVE-2025-13836

* CVE-2025-67724

* CVE-2025-67725

* CVE-2025-67726

CVSS scores:

* CVE-2025-13836 ( SUSE ): 6.3

CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

* CVE-2025-13836 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

* CVE-2025-13836 ( NVD ): 6.3

CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

* CVE-2025-13836 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2026:20820-1
Release Date: 2026-03-24T05:48:50Z
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here