Permissions, Privileges, and Access Controls in Salt - CVE-2025-22241
Published: June 23, 2025
Vulnerability details
The vulnerability allows a local user to bypass implemented security restrictions.
File contents overwrite the VirtKey class is called when “on-demand pillar” data is requested and uses un-validated input to create paths to the “pki directory”. The functionality is used to auto-accept Minion authentication keys based on a pre-placed “authorization file” at a specific location and is present in the default configuration.
Affected software
SUSE Linux Enterprise Server 15 SP3
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise High Performance Computing LTSS 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Micro
SUSE Linux Enterprise Micro for Rancher
SUSE Enterprise Storage
Fedora
SUSE Multi-Linux Manager Client Tools for Debian
openSUSE Leap
SUSE Multi-Linux Manager Client Tools for Ubuntu 22.04
SUSE Multi-Linux Manager Client Tools for Ubuntu 24.04
spacecmd
mgrctl
mgrctl-zsh-completion
mgrctl-bash-completion
mgrctl-fish-completion
venv-salt-minion
salt-bash-completion
salt-fish-completion
salt-minion
salt
python3-salt-testsuite
python3-salt
salt-proxy
salt-cloud
salt-syndic
salt-doc
salt-transactional-update
salt-api
salt-master
salt-ssh
salt-standalone-formulas-configuration
salt-zsh-completion
salt3006
Session Smart Router
How to mitigate CVE-2025-22241
spacecmd - addressed in versions 5.1.8-3.6.1, 5.1.8-3.8.1, 5.1.10-3.11.1
mgrctl - addressed in versions 5.1.14-3.6.1, 5.1.14-3.6.2, 5.1.14-3.8.1
mgrctl-zsh-completion - addressed in versions 5.1.14-3.6.1, 5.1.14-3.6.2, 5.1.14-3.8.1
mgrctl-bash-completion - addressed in versions 5.1.14-3.6.1, 5.1.14-3.6.2, 5.1.14-3.8.1
mgrctl-fish-completion - addressed in versions 5.1.14-3.6.1, 5.1.14-3.6.2, 5.1.14-3.8.1
Session Smart Router - addressed in versions 6.2.10, 6.3.7
venv-salt-minion - addressed in versions 3006.0-3.6.2, 3006.0-3.6.3, 3006.0-3.8.4
salt-bash-completion - update to 3006.0-150300.53.94.1
salt-fish-completion - update to 3006.0-150300.53.94.1
salt-minion - update to 3006.0-150300.53.94.1
salt - update to 3006.0-150300.53.94.1
python3-salt-testsuite - update to 3006.0-150300.53.94.1
python3-salt - update to 3006.0-150300.53.94.1
salt-proxy - update to 3006.0-150300.53.94.1
salt-cloud - update to 3006.0-150300.53.94.1
salt-syndic - update to 3006.0-150300.53.94.1
salt-doc - update to 3006.0-150300.53.94.1
salt-transactional-update - update to 3006.0-150300.53.94.1
salt-api - update to 3006.0-150300.53.94.1
salt-master - update to 3006.0-150300.53.94.1
salt-ssh - update to 3006.0-150300.53.94.1
salt-standalone-formulas-configuration - update to 3006.0-150300.53.94.1
salt-zsh-completion - update to 3006.0-150300.53.94.1
salt3006 - update to 3006.12-1.el9
salt - addressed in versions 3007.4-2.fc43, 3007.4-3.fc42, 3007.4-4.fc41, 3007.4-4.fc42
External References
Related Security Bulletins
- Multiple vulnerabilities in SaltStack Salt
- Fedora EPEL 9 update for salt3006
- Fedora 43 update for salt
- Fedora 42 update for salt
- Fedora 41 update for salt
- Fedora 42 update for salt
- SUSE update for salt
- SUSE update for Security update 5.1.0 GM for Multi-Linux Manager Client Tools
- SUSE update for Security update 5.1.0 GM for Multi-Linux Manager Client Tools
- SUSE update for Security update 5.1.0 GM for Multi-Linux Manager Client Tools
- Juniper Session Smart Router update for third-party components