SUSE SLES15 Security Update : kubevirt (SUSE-SU-2026:3480-1)

high Nessus Plugin ID 332133

Synopsis

The remote SUSE host is missing one or more security updates.

Description

The remote SUSE Linux SLES15 / SLES_SAP15 host has packages installed that are affected by multiple vulnerabilities as referenced in the SUSE-SU-2026:3480-1 advisory.

- Security update correcting a CVE over-claim from the previous update, verified by auditing the fix code actually present in the vendored tree:

* CVE-2026-39821 (bsc#1266575): the previous entry claimed this fixed by the golang.org/x/net v0.55.0 re-vendor, but 0.55.0's idna fix is compile-time gated on Unicode 16 tables, which only exist for go1.27+ - it is inert in our go1.25 builds, so the claim was incorrect. Re-vendor golang.org/x/net v0.55.0 -> v0.57.0, whose idna package rejects all-ASCII Punycode labels unconditionally; the CVE is now actually fixed.

- Re-vendor golang.org/x/text v0.37.0 -> v0.40.0: CVE-2026-56852 (bsc#1271661), infinite loop on invalid input in unicode/norm.

- golang.org/x/crypto v0.52.0 -> v0.54.0 (pulled in by x/net 0.57.0;
no additional CVE claims, all previously listed x/crypto fixes remain included).

- CVE-2026-13201 (bsc#1269093), safepath resolves a path whose last component is a symlink without detecting it, allowing metadata operations via /proc/self/fd to act on the symlink target.
Backports of upstream release-1.7 commits 9ecda4ad5e and 1494cee849.
- x/net 0.57.0 also contains the fix for CVE-2026-46600 (bsc#1272415) in dns/dnsmessage; kubevirt does not vendor that package (not affected), the bump merely rides past it.

Tenable has extracted the preceding description block directly from the SUSE security advisory.

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.

Solution

Update the affected kubevirt-manifests and / or kubevirt-virtctl packages.

See Also

https://bugzilla.suse.com/1266575

https://bugzilla.suse.com/1269093

https://bugzilla.suse.com/1271661

https://bugzilla.suse.com/1272415

https://www.suse.com/security/cve/CVE-2026-13201

https://www.suse.com/security/cve/CVE-2026-39821

https://www.suse.com/security/cve/CVE-2026-46600

https://www.suse.com/security/cve/CVE-2026-56852

http://www.nessus.org/u?6c40c1aa

Plugin Details

Severity: High

ID: 332133

File Name: suse_SU-2026-3480-1.nasl

Version: 1.1

Type: Local

Agent: unix

Published: 8/5/2026

Updated: 8/5/2026

Supported Sensors: Continuous Assessment, Nessus Agent, Nessus

Risk Information

VPR

Risk Factor: Medium

Score: 4.8

Percentile: 57.7

CVSS v2

Risk Factor: Medium

Base Score: 5.2

Temporal Score: 3.8

Vector: CVSS2#AV:L/AC:L/Au:S/C:N/I:P/A:C

CVSS Score Source: CVE-2026-13201

CVSS v3

Risk Factor: High

Base Score: 8.2

Temporal Score: 7.1

Vector: CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

CVSS Score Source: CVE-2026-39821

Vulnerability Information

CPE: cpe:/o:novell:suse_linux:15, p-cpe:/a:novell:suse_linux:kubevirt-manifests, p-cpe:/a:novell:suse_linux:kubevirt-virtctl

Required KB Items: Host/local_checks_enabled, Host/cpu, Host/SuSE/release, Host/SuSE/rpm-list

Exploit Ease: No known exploits are available

Patch Publication Date: 8/4/2026

Vulnerability Publication Date: 5/12/2026

Reference Information

CVE: CVE-2026-13201, CVE-2026-39821, CVE-2026-46600, CVE-2026-56852

SuSE: SUSE-SU-2026:3480-1