{"id":"openSUSE-SU-2026:21590-1","summary":"Security update for kubevirt1.8","details":"This update for kubevirt1.8 fixes the following issues:\n\nUpdate to version 1.8.4.\n\nSecurity issues fixed:\n\n- CVE-2026-13201: virt-handler-rhel9: kubevirt: safepath `OpenAtNoFollow` symlink following via `/proc/self/fd` allows\n  host file metadata modification (bsc#1269093).\n- CVE-2026-13622: virt-handler migration proxy follows symlinks and allows container escape to host (bsc#1272840).\n- CVE-2026-25680, CVE-2026-25681, CVE-2026-27136, CVE-2026-42502, CVE-2026-42506: golang.org/x/net/html: multiple issues\n  when parsing HTML files (bsc#1267120).\n- CVE-2026-33814: golang.org/x/net/http2: processing of HTTP/2 SETTINGS frames with a crafted `SETTINGS_MAX_FRAME_SIZE`\n  can lead to an infinite loop and a denial of service (bsc#1265736).\n- CVE-2026-35469: github.com/moby/spdystream: improper validation of attacker-controlled input in the SPDY/3 frame\n  parser allows for a denial of service via crafted SPDY frames (bsc#1262265).\n- CVE-2026-39821: golang.org/x/net/idna: failure to reject ASCII-only Punycode-encoded labels allows for validation\n  bypass and privilege escalation (bsc#1266575).\n- CVE-2026-39827, CVE-2026-39828, CVE-2026-39829, CVE-2026-39830, CVE-2026-39831, CVE-2026-39832, CVE-2026-39833,\n  CVE-2026-39834, CVE-2026-39835, CVE-2026-42508, CVE-2026-46595, CVE-2026-46597, CVE-2026-46598:\n  golang.org/x/crypto/ssh: multiple issues in `x/crypto/ssh` (bsc#1266151).\n- CVE-2026-46600: parsing of invalid SVCB or HTTPS RR when the size of a parameter value overflows the message buffer\n  can lead to panic (bsc#1273606).\n- CVE-2026-56852: improper handling of truncated/invalid UTF-8 input can lead to an infinite loop (bsc#1272011).\n\n Other updates and bugfixes:\n\n- Fix the release manifests' image references (bsc#1272604).\n- Add a `libguestfs-tools` subpackage.\n- Build with Go \u003e= 1.25 (required by `golang.org/x/net` 0.55).\n- Version 1.8.4:\n  * node-labeller: use new `libvirt` flags for full feature expansion.\n  * Fix gRPC connection leak in `GetLauncherClient`; clean up ghost launcher record on connection setup failure.\n  * api: validate `VMI VSOCK CID` and checksum status fields as `uint32`.\n  * virt-operator: refine canary flow to fully support out-of-band changes.\n  * New `virt-api`/`virt-handler`/`virt-operator` ready and down metrics, alerts and recording rules.\n- Refresh `disks-images-provider.yaml` to the v1.8.4 image tag.\n","modified":"2026-08-21T18:23:45.490195797Z","published":"2026-08-18T16:05:12Z","related":["CVE-2026-13201","CVE-2026-13622","CVE-2026-25680","CVE-2026-25681","CVE-2026-27136","CVE-2026-33814","CVE-2026-35469","CVE-2026-39821","CVE-2026-39827","CVE-2026-39828","CVE-2026-39829","CVE-2026-39830","CVE-2026-39831","CVE-2026-39832","CVE-2026-39833","CVE-2026-39834","CVE-2026-39835","CVE-2026-42502","CVE-2026-42506","CVE-2026-42508","CVE-2026-46595","CVE-2026-46597","CVE-2026-46598","CVE-2026-46600","CVE-2026-56852"],"upstream":["CVE-2026-13201","CVE-2026-13622","CVE-2026-25680","CVE-2026-25681","CVE-2026-27136","CVE-2026-33814","CVE-2026-35469","CVE-2026-39821","CVE-2026-39827","CVE-2026-39828","CVE-2026-39829","CVE-2026-39830","CVE-2026-39831","CVE-2026-39832","CVE-2026-39833","CVE-2026-39834","CVE-2026-39835","CVE-2026-42502","CVE-2026-42506","CVE-2026-42508","CVE-2026-46595","CVE-2026-46597","CVE-2026-46598","CVE-2026-46600","CVE-2026-56852"],"references":[{"type":"ADVISORY"},{"type":"REPORT","url":"https://bugzilla.suse.com/1262265"},{"type":"REPORT","url":"https://bugzilla.suse.com/1265736"},{"type":"REPORT","url":"https://bugzilla.suse.com/1266151"},{"type":"REPORT","url":"https://bugzilla.suse.com/1266575"},{"type":"REPORT","url":"https://bugzilla.suse.com/1267120"},{"type":"REPORT","url":"https://bugzilla.suse.com/1269093"},{"type":"REPORT","url":"https://bugzilla.suse.com/1272011"},{"type":"REPORT","url":"https://bugzilla.suse.com/1272604"},{"type":"REPORT","url":"https://bugzilla.suse.com/1272840"},{"type":"REPORT","url":"https://bugzilla.suse.com/1273606"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-13201"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-13622"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-25680"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-25681"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-27136"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-33814"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-35469"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-39821"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-39827"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-39828"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-39829"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-39830"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-39831"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-39832"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-39833"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-39834"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-39835"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-42502"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-42506"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-42508"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-46595"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-46597"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-46598"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-46600"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-56852"}],"affected":[{"package":{"name":"kubevirt1.8","ecosystem":"openSUSE:Leap 16.0","purl":"pkg:rpm/opensuse/kubevirt1.8&distro=openSUSE%20Leap%2016.0"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.8.4-160000.1.1"}]}],"ecosystem_specific":{"binaries":[{"kubevirt1.8-libguestfs-tools":"1.8.4-160000.1.1","kubevirt1.8-virt-operator":"1.8.4-160000.1.1","kubevirt1.8-tests":"1.8.4-160000.1.1","kubevirt1.8-virt-controller":"1.8.4-160000.1.1","kubevirt1.8-sidecar-shim":"1.8.4-160000.1.1","kubevirt1.8-virt-exportserver":"1.8.4-160000.1.1","kubevirt1.8-virt-api":"1.8.4-160000.1.1","kubevirt1.8-virt-launcher":"1.8.4-160000.1.1","kubevirt1.8-pr-helper-conf":"1.8.4-160000.1.1","kubevirt1.8-virt-exportproxy":"1.8.4-160000.1.1","kubevirt1.8-virtctl":"1.8.4-160000.1.1","kubevirt1.8-virt-synchronization-controller":"1.8.4-160000.1.1","kubevirt1.8-container-disk":"1.8.4-160000.1.1","kubevirt1.8-virt-handler":"1.8.4-160000.1.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2026:21590-1.json"}}],"schema_version":"1.9.0"}