Alerts This Week
Warning Icon 1 525
Alerts This Week
Warning Icon 1 525

SUSE Multi-Linux Manager Important Salt Bundle Update CVE-2026-27448 DoS

suse
Calendar Grey June 3, 2026
Dist Suse Esm H88
SUSE updates Multi-Linux Manager Salt Bundle with important security fixes addressing critical vulnerabilities and risks.
An update that solves three vulnerabilities, contains one feature and has six security fixes can now be installed.

Summary

## This update fixes the following issues: venv-salt-minion: * Security issues fixed: * CVE-2026-31958: tornado: Fixed parsing large multipart bodies with many parts can cause a denial of service (bsc#1259554) * CVE-2026-27459: pyOpenSSL: Fixed issue with large cookie value that can lead to a buffer overflow (bsc#1259808) * CVE-2026-27448: pyOpenSSL: Fixed unhandled exception can result in connection not being cancelled (bsc#1259804) * Other updates and bugfixes: * Use non vendored Tornado with Python 3.11 (bsc#1257583, bsc#1259700) * Hardened Tornado from invalid HTTP reason phrases * Read full URI from ldap pillar config (bsc#1254900) * Make users with backslash work for `salt-ssh` (bsc#1254629). * Fixed `ansible.playbooks` `extra-vars` quoting (bsc#1257831),

References

* bsc#1254629

* bsc#1254900

* bsc#1257583

* bsc#1257831

* bsc#1258957

* bsc#1259554

* bsc#1259700

* bsc#1259804

* bsc#1259808

* jsc#MSQA-1052

Cross-

* CVE-2026-27448

* CVE-2026-27459

* CVE-2026-31958

CVSS scores:

* CVE-2026-27448 ( SUSE ): 6.3

CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N

* CVE-2026-27448 ( SUSE ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N

* CVE-2026-27448 ( NVD ): 1.7

CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

* CVE-2026-27448 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N

* CVE-2026-27459 ( SUSE ): 8.3

CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2026:2246-1
Release Date: 2026-06-03T14:13:17Z
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here