OPENSUSE-SU-2026:21590-1

Advisory lineage Upstream: 25 Downstream: 0
Published: 18 Aug 2026, 16:05
Last modified:21 Aug 2026, 09:15

Vulnerability Summary

Overall Risk (default)
minimal
0/100
CVSS Score
No data
EPSS Score
No data
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

18 Aug 2026, 16:05
Published
Vulnerability first disclosed
21 Aug 2026, 09:15
Last Modified
Vulnerability information updated

Description

Security update for kubevirt1.8 This update for kubevirt1.8 fixes the following issues: Update to version 1.8.4. Security issues fixed: - CVE-2026-13201: virt-handler-rhel9: kubevirt: safepath `OpenAtNoFollow` symlink following via `/proc/self/fd` allows host file metadata modification (bsc#1269093). - CVE-2026-13622: virt-handler migration proxy follows symlinks and allows container escape to host (bsc#1272840). - CVE-2026-25680, CVE-2026-25681, CVE-2026-27136, CVE-2026-42502, CVE-2026-42506: golang.org/x/net/html: multiple issues when parsing HTML files (bsc#1267120). - CVE-2026-33814: golang.org/x/net/http2: processing of HTTP/2 SETTINGS frames with a crafted `SETTINGS_MAX_FRAME_SIZE` can lead to an infinite loop and a denial of service (bsc#1265736). - CVE-2026-35469: github.com/moby/spdystream: improper validation of attacker-controlled input in the SPDY/3 frame parser allows for a denial of service via crafted SPDY frames (bsc#1262265). - CVE-2026-39821: golang.org/x/net/idna: failure to reject ASCII-only Punycode-encoded labels allows for validation bypass and privilege escalation (bsc#1266575). - CVE-2026-39827, CVE-2026-39828, CVE-2026-39829, CVE-2026-39830, CVE-2026-39831, CVE-2026-39832, CVE-2026-39833, CVE-2026-39834, CVE-2026-39835, CVE-2026-42508, CVE-2026-46595, CVE-2026-46597, CVE-2026-46598: golang.org/x/crypto/ssh: multiple issues in `x/crypto/ssh` (bsc#1266151). - CVE-2026-46600: parsing of invalid SVCB or HTTPS RR when the size of a parameter value overflows the message buffer can lead to panic (bsc#1273606). - CVE-2026-56852: improper handling of truncated/invalid UTF-8 input can lead to an infinite loop (bsc#1272011). Other updates and bugfixes: - Fix the release manifests' image references (bsc#1272604). - Add a `libguestfs-tools` subpackage. - Build with Go >= 1.25 (required by `golang.org/x/net` 0.55). - Version 1.8.4: * node-labeller: use new `libvirt` flags for full feature expansion. * Fix gRPC connection leak in `GetLauncherClient`; clean up ghost launcher record on connection setup failure. * api: validate `VMI VSOCK CID` and checksum status fields as `uint32`. * virt-operator: refine canary flow to fully support out-of-band changes. * New `virt-api`/`virt-handler`/`virt-operator` ready and down metrics, alerts and recording rules. - Refresh `disks-images-provider.yaml` to the v1.8.4 image tag.

Affected Systems

  • opensusekubevirt1.8&distro=openSUSE Leap 16.0

    < 1.8.4-160000.1.1

References (35)