OPENSUSE-SU-2026:21590-1
Vulnerability Summary
Timeline
Description
Security update for kubevirt1.8 This update for kubevirt1.8 fixes the following issues: Update to version 1.8.4. Security issues fixed: - CVE-2026-13201: virt-handler-rhel9: kubevirt: safepath `OpenAtNoFollow` symlink following via `/proc/self/fd` allows host file metadata modification (bsc#1269093). - CVE-2026-13622: virt-handler migration proxy follows symlinks and allows container escape to host (bsc#1272840). - CVE-2026-25680, CVE-2026-25681, CVE-2026-27136, CVE-2026-42502, CVE-2026-42506: golang.org/x/net/html: multiple issues when parsing HTML files (bsc#1267120). - CVE-2026-33814: golang.org/x/net/http2: processing of HTTP/2 SETTINGS frames with a crafted `SETTINGS_MAX_FRAME_SIZE` can lead to an infinite loop and a denial of service (bsc#1265736). - CVE-2026-35469: github.com/moby/spdystream: improper validation of attacker-controlled input in the SPDY/3 frame parser allows for a denial of service via crafted SPDY frames (bsc#1262265). - CVE-2026-39821: golang.org/x/net/idna: failure to reject ASCII-only Punycode-encoded labels allows for validation bypass and privilege escalation (bsc#1266575). - CVE-2026-39827, CVE-2026-39828, CVE-2026-39829, CVE-2026-39830, CVE-2026-39831, CVE-2026-39832, CVE-2026-39833, CVE-2026-39834, CVE-2026-39835, CVE-2026-42508, CVE-2026-46595, CVE-2026-46597, CVE-2026-46598: golang.org/x/crypto/ssh: multiple issues in `x/crypto/ssh` (bsc#1266151). - CVE-2026-46600: parsing of invalid SVCB or HTTPS RR when the size of a parameter value overflows the message buffer can lead to panic (bsc#1273606). - CVE-2026-56852: improper handling of truncated/invalid UTF-8 input can lead to an infinite loop (bsc#1272011). Other updates and bugfixes: - Fix the release manifests' image references (bsc#1272604). - Add a `libguestfs-tools` subpackage. - Build with Go >= 1.25 (required by `golang.org/x/net` 0.55). - Version 1.8.4: * node-labeller: use new `libvirt` flags for full feature expansion. * Fix gRPC connection leak in `GetLauncherClient`; clean up ghost launcher record on connection setup failure. * api: validate `VMI VSOCK CID` and checksum status fields as `uint32`. * virt-operator: refine canary flow to fully support out-of-band changes. * New `virt-api`/`virt-handler`/`virt-operator` ready and down metrics, alerts and recording rules. - Refresh `disks-images-provider.yaml` to the v1.8.4 image tag.
Affected Systems
- opensuse•kubevirt1.8&distro=openSUSE Leap 16.0
< 1.8.4-160000.1.1
References (35)
- https://bugzilla.suse.com/1262265
- https://bugzilla.suse.com/1265736
- https://bugzilla.suse.com/1266151
- https://bugzilla.suse.com/1266575
- https://bugzilla.suse.com/1267120
- https://bugzilla.suse.com/1269093
- https://bugzilla.suse.com/1272011
- https://bugzilla.suse.com/1272604
- https://bugzilla.suse.com/1272840
- https://bugzilla.suse.com/1273606
- https://www.suse.com/security/cve/CVE-2026-13201
- https://www.suse.com/security/cve/CVE-2026-13622
- https://www.suse.com/security/cve/CVE-2026-25680
- https://www.suse.com/security/cve/CVE-2026-25681
- https://www.suse.com/security/cve/CVE-2026-27136
- https://www.suse.com/security/cve/CVE-2026-33814
- https://www.suse.com/security/cve/CVE-2026-35469
- https://www.suse.com/security/cve/CVE-2026-39821
- https://www.suse.com/security/cve/CVE-2026-39827
- https://www.suse.com/security/cve/CVE-2026-39828
- https://www.suse.com/security/cve/CVE-2026-39829
- https://www.suse.com/security/cve/CVE-2026-39830
- https://www.suse.com/security/cve/CVE-2026-39831
- https://www.suse.com/security/cve/CVE-2026-39832
- https://www.suse.com/security/cve/CVE-2026-39833
- https://www.suse.com/security/cve/CVE-2026-39834
- https://www.suse.com/security/cve/CVE-2026-39835
- https://www.suse.com/security/cve/CVE-2026-42502
- https://www.suse.com/security/cve/CVE-2026-42506
- https://www.suse.com/security/cve/CVE-2026-42508
- https://www.suse.com/security/cve/CVE-2026-46595
- https://www.suse.com/security/cve/CVE-2026-46597
- https://www.suse.com/security/cve/CVE-2026-46598
- https://www.suse.com/security/cve/CVE-2026-46600
- https://www.suse.com/security/cve/CVE-2026-56852