openSUSE-SU-2026:21590-1

See a problem?
Import Source
https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2026:21590-1.json
JSON Data
https://api.test.osv.dev/v1/vulns/openSUSE-SU-2026:21590-1
Upstream
CVE (25)
Related
Published
2026-08-18T16:05:12Z
Modified
2026-08-21T18:23:45Z
Summary
Security update for kubevirt1.8
Details

This update for kubevirt1.8 fixes the following issues:

Update to version 1.8.4.

Security issues fixed:

  • CVE-2026-13201: virt-handler-rhel9: kubevirt: safepath OpenAtNoFollow symlink following via /proc/self/fd allows host file metadata modification (bsc#1269093).
  • CVE-2026-13622: virt-handler migration proxy follows symlinks and allows container escape to host (bsc#1272840).
  • CVE-2026-25680, CVE-2026-25681, CVE-2026-27136, CVE-2026-42502, CVE-2026-42506: golang.org/x/net/html: multiple issues when parsing HTML files (bsc#1267120).
  • CVE-2026-33814: golang.org/x/net/http2: processing of HTTP/2 SETTINGS frames with a crafted SETTINGS_MAX_FRAME_SIZE can lead to an infinite loop and a denial of service (bsc#1265736).
  • CVE-2026-35469: github.com/moby/spdystream: improper validation of attacker-controlled input in the SPDY/3 frame parser allows for a denial of service via crafted SPDY frames (bsc#1262265).
  • CVE-2026-39821: golang.org/x/net/idna: failure to reject ASCII-only Punycode-encoded labels allows for validation bypass and privilege escalation (bsc#1266575).
  • CVE-2026-39827, CVE-2026-39828, CVE-2026-39829, CVE-2026-39830, CVE-2026-39831, CVE-2026-39832, CVE-2026-39833, CVE-2026-39834, CVE-2026-39835, CVE-2026-42508, CVE-2026-46595, CVE-2026-46597, CVE-2026-46598: golang.org/x/crypto/ssh: multiple issues in x/crypto/ssh (bsc#1266151).
  • CVE-2026-46600: parsing of invalid SVCB or HTTPS RR when the size of a parameter value overflows the message buffer can lead to panic (bsc#1273606).
  • CVE-2026-56852: improper handling of truncated/invalid UTF-8 input can lead to an infinite loop (bsc#1272011).

Other updates and bugfixes:

  • Fix the release manifests' image references (bsc#1272604).
  • Add a libguestfs-tools subpackage.
  • Build with Go >= 1.25 (required by golang.org/x/net 0.55).
  • Version 1.8.4:
    • node-labeller: use new libvirt flags for full feature expansion.
    • Fix gRPC connection leak in GetLauncherClient; clean up ghost launcher record on connection setup failure.
    • api: validate VMI VSOCK CID and checksum status fields as uint32.
    • virt-operator: refine canary flow to fully support out-of-band changes.
    • New virt-api/virt-handler/virt-operator ready and down metrics, alerts and recording rules.
  • Refresh disks-images-provider.yaml to the v1.8.4 image tag.
References

Affected packages

openSUSE:Leap 16.0 / kubevirt1.8

Package

Name
kubevirt1.8
Purl
pkg:rpm/opensuse/kubevirt1.8&distro=openSUSE%20Leap%2016.0

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
1.8.4-160000.1.1

Ecosystem specific

{
    "binaries": [
        {
            "kubevirt1.8-container-disk": "1.8.4-160000.1.1",
            "kubevirt1.8-libguestfs-tools": "1.8.4-160000.1.1",
            "kubevirt1.8-pr-helper-conf": "1.8.4-160000.1.1",
            "kubevirt1.8-sidecar-shim": "1.8.4-160000.1.1",
            "kubevirt1.8-tests": "1.8.4-160000.1.1",
            "kubevirt1.8-virt-api": "1.8.4-160000.1.1",
            "kubevirt1.8-virt-controller": "1.8.4-160000.1.1",
            "kubevirt1.8-virt-exportproxy": "1.8.4-160000.1.1",
            "kubevirt1.8-virt-exportserver": "1.8.4-160000.1.1",
            "kubevirt1.8-virt-handler": "1.8.4-160000.1.1",
            "kubevirt1.8-virt-launcher": "1.8.4-160000.1.1",
            "kubevirt1.8-virt-operator": "1.8.4-160000.1.1",
            "kubevirt1.8-virt-synchronization-controller": "1.8.4-160000.1.1",
            "kubevirt1.8-virtctl": "1.8.4-160000.1.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2026:21590-1.json"