SUSE SLES15 Security Update : kubevirt-1.6, virt-api-container-1.6, virt-controller-container-1.6, virt-exportproxy-container-1.6, virt-exportserver-container-1.6, virt-handler-container-1.6, virt-launcher-container-1.6, virt-libguestfs-tools-container-1.6, virt-operator-container-1.6, virt-pr-helper-container-1.6, virt-synchronization-controller-container-1.6 (SUSE-SU-2026:3630-1)

high Nessus Plugin ID 337974

Language:

Synopsis

The remote SUSE host is missing one or more security updates.

Description

The remote SUSE Linux SLES15 / SLES_SAP15 host has packages installed that are affected by multiple vulnerabilities as referenced in the SUSE-SU-2026:3630-1 advisory.

- CVE-2025-47911: golang.org/x/net/html: algorithms that have quadratic complexity when parsing HTML documents allow for denial of service (bsc#1251420).
- CVE-2025-47914: golang.org/x/crypto/ssh/agent: no validation of message size when processing new identity requests can cause a panic due to an out-of-bounds read (bsc#1254014).
- CVE-2025-58181: golang.org/x/crypto/ssh: no validation of number of mechanisms in GSSAPI authentication requests can cause unbounded memory consumption (bsc#1253935).
- CVE-2025-58190: golang.org/x/net/html: excessive memory consumption by `html.ParseFragment` when processing specially crafted input can lead to a denial of service (bsc#1251615).
- CVE-2026-13201: virt-handler-rhel9: kubevirt: safepath `OpenAtNoFollow` symlink following via `/proc/self/fd` allows host file metadata modification (bsc#1269093).
- CVE-2026-13622: virt-handler migration proxy follows symlinks and allows container escape to host (bsc#1272840).
- CVE-2026-25680,CVE-2026-25681,CVE-2026-27136,CVE-2026-42502,CVE-2026-42506: golang.org/x/net/html:
multiple issues when parsing HTML files (bsc#1267120).
- CVE-2026-33814: golang.org/x/net/http2: processing of HTTP/2 SETTINGS frames with a crafted `SETTINGS_MAX_FRAME_SIZE` can lead to an infinite loop and a denial of service (bsc#1265736).
- CVE-2026-35469: github.com/moby/spdystream: improper validation of attacker-controlled input in the SPDY/3 frame parser allows for a denial of service via crafted SPDY frames (bsc#1262265).
- CVE-2026-39821: golang.org/x/net/idna: failure to reject ASCII-only Punycode-encoded labels allows for validation bypass and privilege escalation (bsc#1266575).
- CVE-2026-46600: parsing of invalid SVCB or HTTPS RR when the size of a parameter value overflows the message buffer can lead to panic (bsc#1273606).
- CVE-2026-56852: improper handling of truncated/invalid UTF-8 input can lead to an infinite loop (bsc#1272000).

Other updates and bugfixes:

- Fixed `printf`-style calls with non-constant format strings (`cmd/virt-chroot`, `tests/`) that fail `go1.25`'s vet (toolchain required by the `x/net` 0.55.0 re-vendor); rewritten with no behavior change.
- Build with Go >= 1.25 (required by `golang.org/x/net` 0.55).

Tenable has extracted the preceding description block directly from the SUSE security advisory.

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.

Solution

Update the affected kubevirt-1.6-manifests and / or kubevirt-1.6-virtctl packages.

See Also

https://bugzilla.suse.com/1251420

https://bugzilla.suse.com/1251615

https://bugzilla.suse.com/1253935

https://bugzilla.suse.com/1254014

https://bugzilla.suse.com/1262265

https://bugzilla.suse.com/1265736

https://bugzilla.suse.com/1266575

https://bugzilla.suse.com/1267120

https://bugzilla.suse.com/1269093

https://bugzilla.suse.com/1272000

https://bugzilla.suse.com/1272840

https://bugzilla.suse.com/1273606

https://lists.suse.com/pipermail/sle-updates/2026-August/049361.html

https://www.suse.com/security/cve/CVE-2025-47911

https://www.suse.com/security/cve/CVE-2025-47914

https://www.suse.com/security/cve/CVE-2025-58181

https://www.suse.com/security/cve/CVE-2025-58190

https://www.suse.com/security/cve/CVE-2026-13201

https://www.suse.com/security/cve/CVE-2026-13622

https://www.suse.com/security/cve/CVE-2026-25680

https://www.suse.com/security/cve/CVE-2026-25681

https://www.suse.com/security/cve/CVE-2026-27136

https://www.suse.com/security/cve/CVE-2026-33814

https://www.suse.com/security/cve/CVE-2026-35469

https://www.suse.com/security/cve/CVE-2026-39821

https://www.suse.com/security/cve/CVE-2026-42502

https://www.suse.com/security/cve/CVE-2026-42506

https://www.suse.com/security/cve/CVE-2026-46600

https://www.suse.com/security/cve/CVE-2026-56852

Plugin Details

Severity: High

ID: 337974

File Name: suse_SU-2026-3630-1.nasl

Version: 1.1

Type: Local

Agent: unix

Published: 8/19/2026

Updated: 8/19/2026

Supported Sensors: Frictionless Assessment AWS, Frictionless Assessment Azure, Frictionless Assessment Agent, Nessus Agent, Agentless Assessment, Continuous Assessment, Tenable Cloud Security, Tenable Self-Hosted Container Security, Nessus

Risk Information

VPR

Risk Factor: Medium

Score: 5.9

Percentile: 96.55

CVSS v2

Risk Factor: High

Base Score: 7.8

Temporal Score: 6.1

Vector: CVSS2#AV:N/AC:L/Au:N/C:N/I:N/A:C

CVSS Score Source: CVE-2026-33814

CVSS v3

Risk Factor: High

Base Score: 7.5

Temporal Score: 6.7

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Temporal Vector: CVSS:3.0/E:P/RL:O/RC:C

CVSS v4

Risk Factor: High

Base Score: 8.7

Threat Score: 7.7

Threat Vector: CVSS:4.0/E:P

Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N

CVSS Score Source: CVE-2026-35469

Vulnerability Information

CPE: cpe:/o:novell:suse_linux:15, p-cpe:/a:novell:suse_linux:kubevirt-1.6-manifests, p-cpe:/a:novell:suse_linux:kubevirt-1.6-virtctl

Required KB Items: Host/local_checks_enabled, Host/cpu, Host/SuSE/release, Host/SuSE/rpm-list

Exploit Available: true

Exploit Ease: Exploits are available

Patch Publication Date: 8/17/2026

Vulnerability Publication Date: 10/23/2025

Reference Information

CVE: CVE-2025-47911, CVE-2025-47914, CVE-2025-58181, CVE-2025-58190, CVE-2026-13201, CVE-2026-13622, CVE-2026-25680, CVE-2026-25681, CVE-2026-27136, CVE-2026-33814, CVE-2026-35469, CVE-2026-39821, CVE-2026-42502, CVE-2026-42506, CVE-2026-46600, CVE-2026-56852

SuSE: SUSE-SU-2026:3630-1