Alerts This Week
Warning Icon 1 525
Alerts This Week
Warning Icon 1 525

openSUSE Salt Important DoS Fix Advisory SUSE-2026-2252-1

suse
Calendar Grey June 3, 2026
Dist Suse Esm H88
This update for salt fixes one important issue and includes five key security fixes across various SUSE distributions.
An update that solves one vulnerability, contains one feature and has five security fixes can now be installed.

Summary

## This update for salt fixes the following issue: Security issues fixed: * CVE-2026-31958: python-tornado: parsing large multipart bodies with many parts can cause a denial of service (bsc#1259554). Other updates and bugfixes: * Use non vendored Tornado with Python 3.11 (bsc#1257583, bsc#1259700) * Harden Tornado from invalid HTTP reason phrases * Read full URI from ldap pillar config (bsc#1254900) * Make users with backslash work for `salt-ssh` (bsc#1254629). * Fixed `ansible.playbooks` `extra-vars` quoting (bsc#1257831), * Fixed `virtualenv` call in test helper to use proper Python version.

References

* bsc#1254629

* bsc#1254900

* bsc#1257583

* bsc#1257831

* bsc#1259554

* bsc#1259700

* jsc#MSQA-1052

Cross-

* CVE-2026-31958

CVSS scores:

* CVE-2026-31958 ( SUSE ): 8.7

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N

* CVE-2026-31958 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

* CVE-2026-31958 ( NVD ): 8.7

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

* CVE-2026-31958 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Affected Products:

* openSUSE Leap 15.4

* SUSE Linux Enterprise High Performance Computing 15 SP4

* SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2026:2252-1
Release Date: 2026-06-03T14:16:35Z
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here