SUSE alert openSUSE-SU-2026:20281-1 (kubevirt)
| From: | null@suse.de | |
| To: | security-announce@lists.opensuse.org | |
| Subject: | openSUSE-SU-2026:20281-1: important: Security update for kubevirt | |
| Date: | Sat, 28 Feb 2026 17:51:50 +0100 | |
| Message-ID: | <20260228165150.DD924FF04@maintenance.suse.de> | |
| Archive-link: | Article |
openSUSE security update: security update for kubevirt ------------------------------------------------------------- Announcement ID: openSUSE-SU-2026:20281-1 Rating: important References: * bsc#1241772 * bsc#1253181 * bsc#1253185 * bsc#1253186 * bsc#1253189 * bsc#1253194 * bsc#1253748 * bsc#1257128 * bsc#1257422 Cross-References: * CVE-2024-45310 * CVE-2025-22872 * CVE-2025-64324 * CVE-2025-64432 * CVE-2025-64433 * CVE-2025-64434 * CVE-2025-64435 * CVE-2025-64437 CVSS scores: * CVE-2024-45310 ( SUSE ): 3.6 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:N/I:L/A:N * CVE-2025-22872 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:L * CVE-2025-22872 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:L/SC:L/SI:L/SA:L * CVE-2025-64324 ( SUSE ): 7.7 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2025-64324 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2025-64432 ( SUSE ): 5.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:H * CVE-2025-64432 ( SUSE ): 5.8 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2025-64433 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N * CVE-2025-64433 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2025-64434 ( SUSE ): 6.3 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:H * CVE-2025-64434 ( SUSE ): 5.8 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2025-64435 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2025-64435 ( SUSE ): 6 CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2025-64437 ( SUSE ): 3.9 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:L/I:L/A:L * CVE-2025-64437 ( SUSE ): 1.8 CVSS:4.0/AV:L/AC:H/AT:N/PR:H/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N Affected Products: openSUSE Leap 16.0 ------------------------------------------------------------- An update that solves 8 vulnerabilities and has 9 bug fixes can now be installed. Description: This update for kubevirt fixes the following issues: Update to version 1.7.0 (bsc#1257128). Security issues fixed: - CVE-2025-64435: logic flaw in the virt-controller can lead to incorrect status updates and potentially causing a DoS (bsc#1253189). - CVE-2024-45310: kubevirt vendored github.com/opencontainers/runc/libcontainer/utils: runc can be tricked into creating empty files/directories on host (bsc#1257422). - CVE-2025-22872: incorrectly interpreted tags can cause content to be placed wrong scope during DOM construction (bsc#1241772). - CVE-2025-64432: fail to correctly validate certain fields in the client TLS certificate may allow an attacker to bypass existing RBAC controls (bsc#1253181). - CVE-2025-64433: improper symlink handling can allow to read arbitrary files (bsc#1253185). - CVE-2025-64434: compromising virt-handler instance can lead to impersonate virt-api and execute privileged operations (bsc#1253186). - CVE-2025-64437: mishandling of symlinks can lead to compromising the CIA (bsc#1253194). - CVE-2025-64324: a logic bug that allows an attacker to read and write arbitrary files owned by more privileged users (bsc#1253748). Other updates and bugfixes: - Upstream now uses stateless firmware for CoCo VMs. Patch instructions: To install this openSUSE security update use the suse recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Leap 16.0 zypper in -t patch openSUSE-Leap-16.0-319=1 Package List: - openSUSE Leap 16.0: kubevirt-container-disk-1.7.0-160000.1.1 kubevirt-manifests-1.7.0-160000.1.1 kubevirt-pr-helper-conf-1.7.0-160000.1.1 kubevirt-sidecar-shim-1.7.0-160000.1.1 kubevirt-tests-1.7.0-160000.1.1 kubevirt-virt-api-1.7.0-160000.1.1 kubevirt-virt-controller-1.7.0-160000.1.1 kubevirt-virt-exportproxy-1.7.0-160000.1.1 kubevirt-virt-exportserver-1.7.0-160000.1.1 kubevirt-virt-handler-1.7.0-160000.1.1 kubevirt-virt-launcher-1.7.0-160000.1.1 kubevirt-virt-operator-1.7.0-160000.1.1 kubevirt-virt-synchronization-controller-1.7.0-160000.1.1 kubevirt-virtctl-1.7.0-160000.1.1 obs-service-kubevirt_containers_meta-1.7.0-160000.1.1 References: * https://www.suse.com/security/cve/CVE-2024-45310.html * https://www.suse.com/security/cve/CVE-2025-22872.html * https://www.suse.com/security/cve/CVE-2025-64324.html * https://www.suse.com/security/cve/CVE-2025-64432.html * https://www.suse.com/security/cve/CVE-2025-64433.html * https://www.suse.com/security/cve/CVE-2025-64434.html * https://www.suse.com/security/cve/CVE-2025-64435.html * https://www.suse.com/security/cve/CVE-2025-64437.html
