Security update for kubevirt, virt-api-container, virt-controller-container, virt-exportproxy-container, virt-exportserver-container, virt-handler-container, virt-launcher-container, virt-libguestfs-t
| Announcement ID: | SUSE-SU-2026:0479-1 |
|---|---|
| Release Date: | 2026-02-12T15:34:12Z |
| Rating: | important |
| References: | |
| Cross-References: | |
| CVSS scores: |
|
| Affected Products: |
|
An update that solves two vulnerabilities and has one security fix can now be installed.
Description:
This update for kubevirt, virt-api-container, virt-controller-container, virt-exportproxy-container, virt-exportserver-container, virt-handler-container, virt-launcher-container, virt-libguestfs-tools-container, virt-operator-container, virt-pr-helper-container, virt-synchronization-controller-container fixes the following issues:
Update to version 1.7.0. (bsc#1257128)
Release notes https://github.com/kubevirt/kubevirt/releases/tag/v1.7.0
- CVE-2025-64435: Fixes logic flaw in the virt-controller can lead to incorrect status updates and potentially causing a DoS (bsc#1253189 )
-
CVE-2024-45310: Fixes kubevirt vendored github.com/opencontainers/runc/libcontainer/utils: runc can be tricked into creating empty files/directories on host bsc#1257422
-
Upstream now uses stateless firmware for CoCo VMs.
Patch Instructions:
To install this SUSE update use the SUSE recommended
installation methods like YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
-
Containers Module 15-SP7
zypper in -t patch SUSE-SLE-Module-Containers-15-SP7-2026-479=1
Package List:
-
Containers Module 15-SP7 (aarch64 x86_64)
- kubevirt-virtctl-1.7.0-150700.3.16.2
- kubevirt-virtctl-debuginfo-1.7.0-150700.3.16.2
- kubevirt-manifests-1.7.0-150700.3.16.2