Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

SUSE-SU-2026:2783-1

Опубликовано: 07 июл. 2026
Источник: suse-cvrf

Описание

Security update for kubevirt-1.6

This update for kubevirt-1.6 fixes the following issues:

  • CVE-2026-9804: Symlink escape in the VMExport dir handler let an attacker controlling an exported PVC read sensitive files (TLS keys, tokens, service-account creds) from the exporter pod. (bsc#1266733)
  • CVE-2025-14525: A VM reporting many guest-internal interfaces via the guest agent could flood VMI status and fill etcd (denial of service). Caps reported interfaces at 10. (bsc#1256434)
  • CVE-2026-35469: resource-exhaustion in the SPDY/3 protocol implementation of github.com/moby/spdystream. (GHSA-pc3f-x583-g7j2,bsc#1262265)

Список пакетов

SUSE Linux Enterprise Module for Containers 15 SP7
kubevirt-1.6-manifests-1.6.6-150700.15.10.1
kubevirt-1.6-virtctl-1.6.6-150700.15.10.1

Описание

A flaw was found in kubevirt. A user within a virtual machine (VM), if the guest agent is active, can exploit this by causing the agent to report an excessive number of network interfaces. This action can overwhelm the system's ability to store VM configuration updates, effectively blocking changes to the Virtual Machine Instance (VMI). This allows the VM user to restrict the VM administrator's ability to manage the VM, leading to a denial of service for administrative operations.


Затронутые продукты
SUSE Linux Enterprise Module for Containers 15 SP7:kubevirt-1.6-manifests-1.6.6-150700.15.10.1
SUSE Linux Enterprise Module for Containers 15 SP7:kubevirt-1.6-virtctl-1.6.6-150700.15.10.1

Ссылки

Описание

spdystream is a Go library for multiplexing streams over SPDY connections. In versions 0.5.0 and below, the SPDY/3 frame parser does not validate attacker-controlled counts and lengths before allocating memory. Three allocation paths are affected: the SETTINGS frame entry count, the header count in parseHeaderValueBlock, and individual header field sizes - all read as 32-bit integers and used directly as allocation sizes with no bounds checking. Because SPDY header blocks are zlib-compressed, a small on-the-wire payload can decompress into large attacker-controlled values. A remote peer that can send SPDY frames to a service using spdystream can exhaust process memory and cause an out-of-memory crash with a single crafted control frame. This issue has been fixed in version 0.5.1.


Затронутые продукты
SUSE Linux Enterprise Module for Containers 15 SP7:kubevirt-1.6-manifests-1.6.6-150700.15.10.1
SUSE Linux Enterprise Module for Containers 15 SP7:kubevirt-1.6-virtctl-1.6.6-150700.15.10.1

Ссылки

Описание

A flaw was found in KubeVirt's virt-exportserver component. An attacker with specific namespace-level access can exploit a path traversal vulnerability in the VMExport directory endpoint. By placing a symbolic link (symlink) within an exported filesystem Persistent Volume Claim (PVC) that points outside its designated mount root, the attacker can read arbitrary files from the exporter pod's filesystem. This leads to information disclosure, potentially exposing sensitive data.


Затронутые продукты
SUSE Linux Enterprise Module for Containers 15 SP7:kubevirt-1.6-manifests-1.6.6-150700.15.10.1
SUSE Linux Enterprise Module for Containers 15 SP7:kubevirt-1.6-virtctl-1.6.6-150700.15.10.1

Ссылки