VYPR

rpm package

opensuse/kubevirt1.9&distro=openSUSE Tumbleweed

pkg:rpm/opensuse/kubevirt1.9&distro=openSUSE%20Tumbleweed

Vulnerabilities (15)

  • CVE-2026-56855HigSep 2, 2026
    affected < 1.9.0-3.1fixed 1.9.0-3.1

    Previously, after a channel has been established, a malicious peer could send crafted messages that would deadlock the entire connection. Now, we handle all RFC 4254 channel messages; global requests are handled explicitly. Then, treat all other messages as a protocol error and t

  • CVE-2026-84304HigSep 1, 2026
    affected < 1.9.0-3.1fixed 1.9.0-3.1

    gRPC-Go is the Go language implementation of gRPC. Prior to 1.83.1, internal/transport/transport.go stores each fragmented HTTP/2 DATA frame as a separate recvMsg in recvBuffer, so millions of one-byte frames can consume disproportionate heap memory even when payload bytes remain

  • CVE-2026-84303MedSep 1, 2026
    affected < 1.9.0-3.1fixed 1.9.0-3.1

    gRPC-Go is the Go language implementation of gRPC. Prior to 1.83.1, the xDS RBAC HTTP filter in internal/xds/httpfilter/rbac/rbac.go does not lowercase header matcher names in normalizeHeaderMatcher even though incoming metadata keys are lowercase. A DENY policy using a mixed-cas

  • CVE-2026-56854HigAug 28, 2026
    affected < 1.9.0-3.1fixed 1.9.0-3.1

    The source-address critical option in the Permissions returned by an authentication callback was only enforced for the PublicKeyCallback and VerifiedPublicKeyCallback paths, extending the fix for CVE-2026-46595. Permissions returned by the PasswordCallback, KeyboardInteractiveCal

  • CVE-2026-13622HigAug 12, 2026
    affected < 1.9.0-3.1fixed 1.9.0-3.1

    A symlink following vulnerability was found in KubeVirt's virt-handler migration proxy. During live migration, virt-handler dials Unix sockets inside the target virt-launcher pod via /proc//root/ paths using net.Dial() without symlink protection. These socket paths reside in

  • CVE-2026-56852HigJul 21, 2026
    affected < 1.9.0-1.1fixed 1.9.0-1.1

    A norm.Iter can enter an infinite loop when handling input containing invalid UTF-8 bytes.

  • CVE-2026-13201HigJun 24, 2026
    affected < 1.9.0-1.1fixed 1.9.0-1.1

    A flaw was found in KubeVirt's safepath package used by virt-handler. The OpenAtNoFollow function uses O_PATH|O_NOFOLLOW to obtain a file descriptor to a path leaf, but downstream operations resolve the path via /proc/self/fd/N using link-following syscalls. When the leaf is a sy

  • CVE-2026-39821CriMay 22, 2026
    affected < 1.9.0-1.1fixed 1.9.0-1.1

    The ToASCII and ToUnicode functions incorrectly accept Punycode-encoded labels that decode to an ASCII-only label. For example, ToUnicode("xn--example-.com") incorrectly returns the name "example.com" rather than an error. This behavior can lead to privilege escalation in program

  • CVE-2026-27136MedMay 22, 2026
    affected < 1.9.0-1.1fixed 1.9.0-1.1

    Parsing arbitrary HTML which is then rendered using Render can result in an unexpected HTML tree. This can be leveraged to execute XSS attacks in applications that attempt to sanitize input HTML before rendering.

  • CVE-2026-42508CriMay 22, 2026
    affected < 1.9.0-1.1fixed 1.9.0-1.1

    Previously, a revoked 'SignatureKey' belonging to a CA was not correctly checked for revocation. Now, both the 'key' and 'key.SignatureKey' are checked for @revoked.

  • CVE-2026-39832CriMay 22, 2026
    affected < 1.9.0-1.1fixed 1.9.0-1.1

    When adding a key to a remote agent constraint extensions such as [email protected] were not serialized in the request. Destination restrictions were silently stripped when forwarding keys, allowing unrestricted use of the key on the remote host. The client now

  • CVE-2026-39828MedMay 22, 2026
    affected < 1.9.0-1.1fixed 1.9.0-1.1

    When an SSH server authentication callback returned PartialSuccessError with non-nil Permissions, those permissions were silently discarded, potentially dropping certificate restrictions such as force-command after a second factor succeeded. Returning non-nil Permissions with Par

  • CVE-2026-39827MedMay 22, 2026
    affected < 1.9.0-1.1fixed 1.9.0-1.1

    An authenticated SSH client that repeatedly opened channels which were rejected by the server caused unbounded memory growth, eventually crashing the server process and affecting all connected users. Rejected channels are now properly removed from the connection's internal state

  • CVE-2025-58190MedFeb 5, 2026
    affected < 1.9.0-1.1fixed 1.9.0-1.1

    The html.Parse function in golang.org/x/net/html has an infinite parsing loop when processing certain inputs, which can lead to denial of service (DoS) if an attacker provides specially crafted HTML content.

  • CVE-2025-47911MedFeb 5, 2026
    affected < 1.9.0-1.1fixed 1.9.0-1.1

    The html.Parse function in golang.org/x/net/html has quadratic parsing complexity when processing certain inputs, which can lead to denial of service (DoS) if an attacker provides specially crafted HTML content.