[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"repo-stars":3,"vuln-SUSE-SU-2026:3480-1":6},{"stargazers_count":4,"fetched_at":5},8,"2026-09-19T11:35:27.363Z",{"id":7,"descriptions":8,"cisa":9,"weaknesses":10,"exploits":11,"aliases":12,"duplicate_of":9,"upstream":13,"downstream":22,"duplicates":23,"related":24,"reserved_at":9,"published_at":29,"modified_at":30,"state":9,"summary":31,"references_raw":33,"kevs":74,"epss":9,"epss_history":75,"metrics":76,"affected":77},"SUSE-SU-2026:3480-1","Security update for kubevirt\n\nThis update for kubevirt fixes the following issues:\n\n- Security update correcting a CVE over-claim from the previous\n  update, verified by auditing the fix code actually present in the\n  vendored tree:\n\n  * CVE-2026-39821 (bsc#1266575): the previous entry claimed this\n    fixed by the golang.org/x/net v0.55.0 re-vendor, but 0.55.0's\n    idna fix is compile-time gated on Unicode 16 tables, which only\n    exist for go1.27+ - it is inert in our go1.25 builds, so the\n    claim was incorrect. Re-vendor golang.org/x/net v0.55.0 ->\n    v0.57.0, whose idna package rejects all-ASCII Punycode labels\n    unconditionally; the CVE is now actually fixed.\n\n- Re-vendor golang.org/x/text v0.37.0 -> v0.40.0: CVE-2026-56852\n  (bsc#1271661), infinite loop on invalid input in unicode/norm.\n\n- golang.org/x/crypto v0.52.0 -> v0.54.0 (pulled in by x/net 0.57.0;\n  no additional CVE claims, all previously listed x/crypto fixes\n  remain included).\n\n- CVE-2026-13201 (bsc#1269093), safepath resolves a path whose last\n  component is a symlink without detecting it, allowing metadata\n  operations via /proc/self/fd to act on the symlink target.\n  Backports of upstream release-1.7 commits 9ecda4ad5e and\n  1494cee849.\n- x/net 0.57.0 also contains the fix for CVE-2026-46600\n  (bsc#1272415) in dns/dnsmessage; kubevirt does not vendor that\n  package (not affected), the bump merely rides past it.\n",null,[],[],[],[14,16,18,20],{"_key":15},"CVE-2026-13201",{"_key":17},"CVE-2026-39821",{"_key":19},"CVE-2026-46600",{"_key":21},"CVE-2026-56852",[],[],[25,26,27,28],{"_key":15},{"_key":17},{"_key":19},{"_key":21},"2026-08-04T11:42:30Z","2026-08-05T18:23:50.365428527Z",{"cisa_kev":32,"cisa_ransomware":32,"cisa_vendor":9,"epss_severity":9,"epss_score":9,"severity":9,"severity_score":9,"severity_version":9,"severity_source":9,"severity_vector":9,"severity_status":9},false,[34,40,45,49,53,57,62,66,70],{"url":35,"sources":36,"tags":38},"https://www.suse.com/support/update/announcement/2026/suse-su-20263480-1/",[37],"osv_suse",[39],"Advisory",{"url":41,"sources":42,"tags":43},"https://bugzilla.suse.com/1266575",[37],[44],"REPORT",{"url":46,"sources":47,"tags":48},"https://bugzilla.suse.com/1269093",[37],[44],{"url":50,"sources":51,"tags":52},"https://bugzilla.suse.com/1271661",[37],[44],{"url":54,"sources":55,"tags":56},"https://bugzilla.suse.com/1272415",[37],[44],{"url":58,"sources":59,"tags":60},"https://www.suse.com/security/cve/CVE-2026-13201",[37],[61],"WEB",{"url":63,"sources":64,"tags":65},"https://www.suse.com/security/cve/CVE-2026-39821",[37],[61],{"url":67,"sources":68,"tags":69},"https://www.suse.com/security/cve/CVE-2026-46600",[37],[61],{"url":71,"sources":72,"tags":73},"https://www.suse.com/security/cve/CVE-2026-56852",[37],[61],[],[],[],[78],{"ecosystem":79,"name":80,"vendor":81,"product":82,"cpe_part":9,"purl_type":83,"purl_namespace":81,"purl_name":82,"source":9,"versions":84},"SUSE Linux Enterprise","kubevirt","suse","kubevirt&distro=SUSE Linux Enterprise Module for Containers 15 SP7","rpm",[85],{"version":86,"is_range":87,"range_type":88,"version_start":9,"version_start_type":9,"version_end":89,"version_end_type":90,"fixed_in":9},"lt1_7_4_150700_3_33_1",true,"ecosystem","1.7.4-150700.3.33.1","excluding"]