VYPR

rpm package

opensuse/kubevirt1.8&distro=openSUSE Tumbleweed

pkg:rpm/opensuse/kubevirt1.8&distro=openSUSE%20Tumbleweed

Vulnerabilities (20)

  • CVE-2026-56852HigJul 21, 2026
    affected < 1.8.4-3.1fixed 1.8.4-3.1

    A norm.Iter can enter an infinite loop when handling input containing invalid UTF-8 bytes.

  • CVE-2026-46600HigJul 21, 2026
    affected < 1.8.4-3.1fixed 1.8.4-3.1

    Parsing an invalid SVCB or HTTPS RR can panic when the size of a parameter value overflows the message buffer.

  • CVE-2026-13201HigJun 24, 2026
    affected < 1.8.4-3.1fixed 1.8.4-3.1

    A flaw was found in KubeVirt's safepath package used by virt-handler. The OpenAtNoFollow function uses O_PATH|O_NOFOLLOW to obtain a file descriptor to a path leaf, but downstream operations resolve the path via /proc/self/fd/N using link-following syscalls. When the leaf is a sy

  • CVE-2026-9804HigMay 28, 2026
    affected < 1.8.3-1.1fixed 1.8.3-1.1

    A flaw was found in KubeVirt's virt-exportserver component. An attacker with specific namespace-level access can exploit a path traversal vulnerability in the VMExport directory endpoint. By placing a symbolic link (symlink) within an exported filesystem Persistent Volume Claim (

  • CVE-2026-39821CriMay 22, 2026
    affected < 1.8.4-2.1fixed 1.8.4-2.1

    The ToASCII and ToUnicode functions incorrectly accept Punycode-encoded labels that decode to an ASCII-only label. For example, ToUnicode("xn--example-.com") incorrectly returns the name "example.com" rather than an error. This behavior can lead to privilege escalation in program

  • CVE-2026-27136MedMay 22, 2026
    affected < 1.8.4-2.1fixed 1.8.4-2.1

    Parsing arbitrary HTML which is then rendered using Render can result in an unexpected HTML tree. This can be leveraged to execute XSS attacks in applications that attempt to sanitize input HTML before rendering.

  • CVE-2026-42508CriMay 22, 2026
    affected < 1.8.4-2.1fixed 1.8.4-2.1

    Previously, a revoked 'SignatureKey' belonging to a CA was not correctly checked for revocation. Now, both the 'key' and 'key.SignatureKey' are checked for @revoked.

  • CVE-2026-39832CriMay 22, 2026
    affected < 1.8.4-2.1fixed 1.8.4-2.1

    When adding a key to a remote agent constraint extensions such as [email protected] were not serialized in the request. Destination restrictions were silently stripped when forwarding keys, allowing unrestricted use of the key on the remote host. The client now

  • CVE-2026-39828MedMay 22, 2026
    affected < 1.8.4-2.1fixed 1.8.4-2.1

    When an SSH server authentication callback returned PartialSuccessError with non-nil Permissions, those permissions were silently discarded, potentially dropping certificate restrictions such as force-command after a second factor succeeded. Returning non-nil Permissions with Par

  • CVE-2026-39827MedMay 22, 2026
    affected < 1.8.4-2.1fixed 1.8.4-2.1

    An authenticated SSH client that repeatedly opened channels which were rejected by the server caused unbounded memory growth, eventually crashing the server process and affecting all connected users. Rejected channels are now properly removed from the connection's internal state

  • CVE-2026-33814HigMay 7, 2026
    affected < 1.8.4-2.1fixed 1.8.4-2.1

    When processing HTTP/2 SETTINGS frames, transport will enter an infinite loop of writing CONTINUATION frames if it receives a SETTINGS_MAX_FRAME_SIZE with a value of 0.

  • CVE-2026-35469MedApr 16, 2026
    affected < 1.8.4-1.1fixed 1.8.4-1.1

    spdystream is a Go library for multiplexing streams over SPDY connections. In versions 0.5.0 and below, the SPDY/3 frame parser does not validate attacker-controlled counts and lengths before allocating memory. Three allocation paths are affected: the SETTINGS frame entry count,

  • CVE-2026-33186CriMar 20, 2026
    affected < 1.8.3-1.1fixed 1.8.3-1.1

    gRPC-Go is the Go language implementation of gRPC. Versions prior to 1.79.3 have an authorization bypass resulting from improper input validation of the HTTP/2 `:path` pseudo-header. The gRPC-Go server was too lenient in its routing logic, accepting requests where the `:path` omi

  • CVE-2025-64437MedNov 7, 2025
    affected < 1.8.3-1.1fixed 1.8.3-1.1

    KubeVirt is a virtual machine management add-on for Kubernetes. In versions before 1.5.3 and 1.6.1, the virt-handler does not verify whether the launcher-sock is a symlink or a regular file. This oversight can be exploited, for example, to change the ownership of arbitrary files

  • CVE-2025-64433MedNov 7, 2025
    affected < 1.8.3-1.1fixed 1.8.3-1.1

    KubeVirt is a virtual machine management add-on for Kubernetes. Prior to 1.5.3 and 1.6.1, a vulnerability was discovered that allows a VM to read arbitrary files from the virt-launcher pod's file system. This issue stems from improper symlink handling when mounting PVC disks into

  • CVE-2025-22872MedApr 16, 2025
    affected < 1.8.3-1.1fixed 1.8.3-1.1

    The tokenizer incorrectly interprets tags with unquoted attribute values that end with a solidus character (/) as self-closing. When directly using Tokenizer, this can result in such tags incorrectly being marked as self-closing, and when using the Parse functions, this can resul

  • CVE-2024-33394MedMay 2, 2024
    affected < 1.8.3-1.1fixed 1.8.3-1.1

    An issue in kubevirt kubevirt v1.2.0 and before allows a local attacker to execute arbitrary code via a crafted command to get the token component.

  • CVE-2023-44487HigKEVOct 10, 2023
    affected < 1.8.3-1.1fixed 1.8.3-1.1

    The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023.

  • CVE-2023-26484HigMar 15, 2023
    affected < 1.8.3-1.1fixed 1.8.3-1.1

    KubeVirt is a virtual machine management add-on for Kubernetes. In versions 0.59.0 and prior, if a malicious user has taken over a Kubernetes node where virt-handler (the KubeVirt node-daemon) is running, the virt-handler service account can be used to modify all node specs. This

  • CVE-2021-43565HigSep 6, 2022
    affected < 1.8.3-1.1fixed 1.8.3-1.1

    The x/crypto/ssh package before 0.0.0-20211202192323-5770296d904e of golang.org/x/crypto allows an attacker to panic an SSH server.