{"schema_version":"1.8.0","id":"SUSE-SU-2026:3480-1","published":"2026-08-04T11:42:30Z","modified":"2026-08-05T18:23:50.365428527Z","related":["CVE-2026-13201","CVE-2026-39821","CVE-2026-46600","CVE-2026-56852"],"upstream":["CVE-2026-13201","CVE-2026-39821","CVE-2026-46600","CVE-2026-56852"],"summary":"Security update for kubevirt","details":"This update for kubevirt fixes the following issues:\n\n- Security update correcting a CVE over-claim from the previous\n  update, verified by auditing the fix code actually present in the\n  vendored tree:\n\n  * CVE-2026-39821 (bsc#1266575): the previous entry claimed this\n    fixed by the golang.org/x/net v0.55.0 re-vendor, but 0.55.0's\n    idna fix is compile-time gated on Unicode 16 tables, which only\n    exist for go1.27+ - it is inert in our go1.25 builds, so the\n    claim was incorrect. Re-vendor golang.org/x/net v0.55.0 ->\n    v0.57.0, whose idna package rejects all-ASCII Punycode labels\n    unconditionally; the CVE is now actually fixed.\n\n- Re-vendor golang.org/x/text v0.37.0 -> v0.40.0: CVE-2026-56852\n  (bsc#1271661), infinite loop on invalid input in unicode/norm.\n\n- golang.org/x/crypto v0.52.0 -> v0.54.0 (pulled in by x/net 0.57.0;\n  no additional CVE claims, all previously listed x/crypto fixes\n  remain included).\n\n- CVE-2026-13201 (bsc#1269093), safepath resolves a path whose last\n  component is a symlink without detecting it, allowing metadata\n  operations via /proc/self/fd to act on the symlink target.\n  Backports of upstream release-1.7 commits 9ecda4ad5e and\n  1494cee849.\n- x/net 0.57.0 also contains the fix for CVE-2026-46600\n  (bsc#1272415) in dns/dnsmessage; kubevirt does not vendor that\n  package (not affected), the bump merely rides past it.\n","affected":[{"package":{"name":"kubevirt","ecosystem":"SUSE:Linux Enterprise Module for Containers 15 SP7","purl":"pkg:rpm/suse/kubevirt&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Containers%2015%20SP7"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.7.4-150700.3.33.1"}]}],"ecosystem_specific":{"binaries":[{"kubevirt-manifests":"1.7.4-150700.3.33.1","kubevirt-virtctl":"1.7.4-150700.3.33.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:3480-1.json"}}],"references":[{"type":"ADVISORY","url":"https://www.suse.com/support/update/announcement/2026/suse-su-20263480-1/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1266575"},{"type":"REPORT","url":"https://bugzilla.suse.com/1269093"},{"type":"REPORT","url":"https://bugzilla.suse.com/1271661"},{"type":"REPORT","url":"https://bugzilla.suse.com/1272415"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-13201"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-39821"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-46600"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-56852"}]}