[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"repo-stars":3,"vuln-OPENSUSE-SU-2026:21590-1":6},{"stargazers_count":4,"fetched_at":5},8,"2026-09-19T11:35:27.363Z",{"id":7,"descriptions":8,"cisa":9,"weaknesses":10,"exploits":11,"aliases":12,"duplicate_of":9,"upstream":13,"downstream":64,"duplicates":65,"related":66,"reserved_at":9,"published_at":92,"modified_at":93,"state":9,"summary":94,"references_raw":96,"kevs":240,"epss":9,"epss_history":241,"metrics":242,"affected":243},"OPENSUSE-SU-2026:21590-1","Security update for kubevirt1.8\n\nThis update for kubevirt1.8 fixes the following issues:\n\nUpdate to version 1.8.4.\n\nSecurity issues fixed:\n\n- CVE-2026-13201: virt-handler-rhel9: kubevirt: safepath `OpenAtNoFollow` symlink following via `/proc/self/fd` allows\n  host file metadata modification (bsc#1269093).\n- CVE-2026-13622: virt-handler migration proxy follows symlinks and allows container escape to host (bsc#1272840).\n- CVE-2026-25680, CVE-2026-25681, CVE-2026-27136, CVE-2026-42502, CVE-2026-42506: golang.org/x/net/html: multiple issues\n  when parsing HTML files (bsc#1267120).\n- CVE-2026-33814: golang.org/x/net/http2: processing of HTTP/2 SETTINGS frames with a crafted `SETTINGS_MAX_FRAME_SIZE`\n  can lead to an infinite loop and a denial of service (bsc#1265736).\n- CVE-2026-35469: github.com/moby/spdystream: improper validation of attacker-controlled input in the SPDY/3 frame\n  parser allows for a denial of service via crafted SPDY frames (bsc#1262265).\n- CVE-2026-39821: golang.org/x/net/idna: failure to reject ASCII-only Punycode-encoded labels allows for validation\n  bypass and privilege escalation (bsc#1266575).\n- CVE-2026-39827, CVE-2026-39828, CVE-2026-39829, CVE-2026-39830, CVE-2026-39831, CVE-2026-39832, CVE-2026-39833,\n  CVE-2026-39834, CVE-2026-39835, CVE-2026-42508, CVE-2026-46595, CVE-2026-46597, CVE-2026-46598:\n  golang.org/x/crypto/ssh: multiple issues in `x/crypto/ssh` (bsc#1266151).\n- CVE-2026-46600: parsing of invalid SVCB or HTTPS RR when the size of a parameter value overflows the message buffer\n  can lead to panic (bsc#1273606).\n- CVE-2026-56852: improper handling of truncated/invalid UTF-8 input can lead to an infinite loop (bsc#1272011).\n\n Other updates and bugfixes:\n\n- Fix the release manifests' image references (bsc#1272604).\n- Add a `libguestfs-tools` subpackage.\n- Build with Go >= 1.25 (required by `golang.org/x/net` 0.55).\n- Version 1.8.4:\n  * node-labeller: use new `libvirt` flags for full feature expansion.\n  * Fix gRPC connection leak in `GetLauncherClient`; clean up ghost launcher record on connection setup failure.\n  * api: validate `VMI VSOCK CID` and checksum status fields as `uint32`.\n  * virt-operator: refine canary flow to fully support out-of-band changes.\n  * New `virt-api`/`virt-handler`/`virt-operator` ready and down metrics, alerts and recording rules.\n- Refresh `disks-images-provider.yaml` to the v1.8.4 image tag.\n",null,[],[],[],[14,16,18,20,22,24,26,28,30,32,34,36,38,40,42,44,46,48,50,52,54,56,58,60,62],{"_key":15},"CVE-2026-13201",{"_key":17},"CVE-2026-13622",{"_key":19},"CVE-2026-25680",{"_key":21},"CVE-2026-25681",{"_key":23},"CVE-2026-27136",{"_key":25},"CVE-2026-33814",{"_key":27},"CVE-2026-35469",{"_key":29},"CVE-2026-39821",{"_key":31},"CVE-2026-39827",{"_key":33},"CVE-2026-39828",{"_key":35},"CVE-2026-39829",{"_key":37},"CVE-2026-39830",{"_key":39},"CVE-2026-39831",{"_key":41},"CVE-2026-39832",{"_key":43},"CVE-2026-39833",{"_key":45},"CVE-2026-39834",{"_key":47},"CVE-2026-39835",{"_key":49},"CVE-2026-42502",{"_key":51},"CVE-2026-42506",{"_key":53},"CVE-2026-42508",{"_key":55},"CVE-2026-46595",{"_key":57},"CVE-2026-46597",{"_key":59},"CVE-2026-46598",{"_key":61},"CVE-2026-46600",{"_key":63},"CVE-2026-56852",[],[],[67,68,69,70,71,72,73,74,75,76,77,78,79,80,81,82,83,84,85,86,87,88,89,90,91],{"_key":15},{"_key":17},{"_key":19},{"_key":21},{"_key":23},{"_key":25},{"_key":27},{"_key":29},{"_key":31},{"_key":33},{"_key":35},{"_key":37},{"_key":39},{"_key":41},{"_key":43},{"_key":45},{"_key":47},{"_key":49},{"_key":51},{"_key":53},{"_key":55},{"_key":57},{"_key":59},{"_key":61},{"_key":63},"2026-08-18T16:05:12Z","2026-08-21T09:15:09.273633061Z",{"cisa_kev":95,"cisa_ransomware":95,"cisa_vendor":9,"epss_severity":9,"epss_score":9,"severity":9,"severity_score":9,"severity_version":9,"severity_source":9,"severity_vector":9,"severity_status":9},false,[97,103,107,111,115,119,123,127,131,135,139,144,148,152,156,160,164,168,172,176,180,184,188,192,196,200,204,208,212,216,220,224,228,232,236],{"url":98,"sources":99,"tags":101},"https://bugzilla.suse.com/1262265",[100],"osv_opensuse",[102],"REPORT",{"url":104,"sources":105,"tags":106},"https://bugzilla.suse.com/1265736",[100],[102],{"url":108,"sources":109,"tags":110},"https://bugzilla.suse.com/1266151",[100],[102],{"url":112,"sources":113,"tags":114},"https://bugzilla.suse.com/1266575",[100],[102],{"url":116,"sources":117,"tags":118},"https://bugzilla.suse.com/1267120",[100],[102],{"url":120,"sources":121,"tags":122},"https://bugzilla.suse.com/1269093",[100],[102],{"url":124,"sources":125,"tags":126},"https://bugzilla.suse.com/1272011",[100],[102],{"url":128,"sources":129,"tags":130},"https://bugzilla.suse.com/1272604",[100],[102],{"url":132,"sources":133,"tags":134},"https://bugzilla.suse.com/1272840",[100],[102],{"url":136,"sources":137,"tags":138},"https://bugzilla.suse.com/1273606",[100],[102],{"url":140,"sources":141,"tags":142},"https://www.suse.com/security/cve/CVE-2026-13201",[100],[143],"WEB",{"url":145,"sources":146,"tags":147},"https://www.suse.com/security/cve/CVE-2026-13622",[100],[143],{"url":149,"sources":150,"tags":151},"https://www.suse.com/security/cve/CVE-2026-25680",[100],[143],{"url":153,"sources":154,"tags":155},"https://www.suse.com/security/cve/CVE-2026-25681",[100],[143],{"url":157,"sources":158,"tags":159},"https://www.suse.com/security/cve/CVE-2026-27136",[100],[143],{"url":161,"sources":162,"tags":163},"https://www.suse.com/security/cve/CVE-2026-33814",[100],[143],{"url":165,"sources":166,"tags":167},"https://www.suse.com/security/cve/CVE-2026-35469",[100],[143],{"url":169,"sources":170,"tags":171},"https://www.suse.com/security/cve/CVE-2026-39821",[100],[143],{"url":173,"sources":174,"tags":175},"https://www.suse.com/security/cve/CVE-2026-39827",[100],[143],{"url":177,"sources":178,"tags":179},"https://www.suse.com/security/cve/CVE-2026-39828",[100],[143],{"url":181,"sources":182,"tags":183},"https://www.suse.com/security/cve/CVE-2026-39829",[100],[143],{"url":185,"sources":186,"tags":187},"https://www.suse.com/security/cve/CVE-2026-39830",[100],[143],{"url":189,"sources":190,"tags":191},"https://www.suse.com/security/cve/CVE-2026-39831",[100],[143],{"url":193,"sources":194,"tags":195},"https://www.suse.com/security/cve/CVE-2026-39832",[100],[143],{"url":197,"sources":198,"tags":199},"https://www.suse.com/security/cve/CVE-2026-39833",[100],[143],{"url":201,"sources":202,"tags":203},"https://www.suse.com/security/cve/CVE-2026-39834",[100],[143],{"url":205,"sources":206,"tags":207},"https://www.suse.com/security/cve/CVE-2026-39835",[100],[143],{"url":209,"sources":210,"tags":211},"https://www.suse.com/security/cve/CVE-2026-42502",[100],[143],{"url":213,"sources":214,"tags":215},"https://www.suse.com/security/cve/CVE-2026-42506",[100],[143],{"url":217,"sources":218,"tags":219},"https://www.suse.com/security/cve/CVE-2026-42508",[100],[143],{"url":221,"sources":222,"tags":223},"https://www.suse.com/security/cve/CVE-2026-46595",[100],[143],{"url":225,"sources":226,"tags":227},"https://www.suse.com/security/cve/CVE-2026-46597",[100],[143],{"url":229,"sources":230,"tags":231},"https://www.suse.com/security/cve/CVE-2026-46598",[100],[143],{"url":233,"sources":234,"tags":235},"https://www.suse.com/security/cve/CVE-2026-46600",[100],[143],{"url":237,"sources":238,"tags":239},"https://www.suse.com/security/cve/CVE-2026-56852",[100],[143],[],[],[],[244],{"ecosystem":245,"name":246,"vendor":247,"product":248,"cpe_part":9,"purl_type":249,"purl_namespace":247,"purl_name":248,"source":9,"versions":250},"openSUSE","kubevirt1.8","opensuse","kubevirt1.8&distro=openSUSE Leap 16.0","rpm",[251],{"version":252,"is_range":253,"range_type":254,"version_start":9,"version_start_type":9,"version_end":255,"version_end_type":256,"fixed_in":9},"lt1_8_4_160000_1_1",true,"ecosystem","1.8.4-160000.1.1","excluding"]