SUSE-SU-2026:20571-1
Vulnerability Summary
Timeline
Description
Security update for kubevirt This update for kubevirt fixes the following issues: Update to version 1.7.0 (bsc#1257128). Security issues fixed: - CVE-2025-64435: logic flaw in the virt-controller can lead to incorrect status updates and potentially causing a DoS (bsc#1253189). - CVE-2024-45310: kubevirt vendored github.com/opencontainers/runc/libcontainer/utils: runc can be tricked into creating empty files/directories on host (bsc#1257422). - CVE-2025-22872: incorrectly interpreted tags can cause content to be placed wrong scope during DOM construction (bsc#1241772). - CVE-2025-64432: fail to correctly validate certain fields in the client TLS certificate may allow an attacker to bypass existing RBAC controls (bsc#1253181). - CVE-2025-64433: improper symlink handling can allow to read arbitrary files (bsc#1253185). - CVE-2025-64434: compromising virt-handler instance can lead to impersonate virt-api and execute privileged operations (bsc#1253186). - CVE-2025-64437: mishandling of symlinks can lead to compromising the CIA (bsc#1253194). - CVE-2025-64324: a logic bug that allows an attacker to read and write arbitrary files owned by more privileged users (bsc#1253748). Other updates and bugfixes: - Upstream now uses stateless firmware for CoCo VMs.
Affected Systems
- suse•kubevirt&distro=SUSE Linux Micro Extras 6.2
< 1.7.0-160000.1.1
References (18)
- https://www.suse.com/support/update/announcement/2026/suse-su-202620571-1/
- https://bugzilla.suse.com/1241772
- https://bugzilla.suse.com/1253181
- https://bugzilla.suse.com/1253185
- https://bugzilla.suse.com/1253186
- https://bugzilla.suse.com/1253189
- https://bugzilla.suse.com/1253194
- https://bugzilla.suse.com/1253748
- https://bugzilla.suse.com/1257128
- https://bugzilla.suse.com/1257422
- https://www.suse.com/security/cve/CVE-2024-45310
- https://www.suse.com/security/cve/CVE-2025-22872
- https://www.suse.com/security/cve/CVE-2025-64324
- https://www.suse.com/security/cve/CVE-2025-64432
- https://www.suse.com/security/cve/CVE-2025-64433
- https://www.suse.com/security/cve/CVE-2025-64434
- https://www.suse.com/security/cve/CVE-2025-64435
- https://www.suse.com/security/cve/CVE-2025-64437