openSUSE 16: kubevirt1.8-container-disk / kubevirt1.8-libguestfs-tools / etc (openSUSE-SU-2026:21590-1)

high Nessus Plugin ID 338629

Language:

Synopsis

The remote openSUSE host is missing one or more security updates.

Description

The remote openSUSE 16 host has packages installed that are affected by multiple vulnerabilities as referenced in the openSUSE-SU-2026:21590-1 advisory.

Update to version 1.8.4.

Security issues fixed:

- CVE-2026-13201: virt-handler-rhel9: kubevirt: safepath `OpenAtNoFollow` symlink following via `/proc/self/fd` allows host file metadata modification (bsc#1269093).
- CVE-2026-13622: virt-handler migration proxy follows symlinks and allows container escape to host (bsc#1272840).
- CVE-2026-25680, CVE-2026-25681, CVE-2026-27136, CVE-2026-42502, CVE-2026-42506: golang.org/x/net/html:
multiple issues when parsing HTML files (bsc#1267120).
- CVE-2026-33814: golang.org/x/net/http2: processing of HTTP/2 SETTINGS frames with a crafted `SETTINGS_MAX_FRAME_SIZE` can lead to an infinite loop and a denial of service (bsc#1265736).
- CVE-2026-35469: github.com/moby/spdystream: improper validation of attacker-controlled input in the SPDY/3 frame parser allows for a denial of service via crafted SPDY frames (bsc#1262265).
- CVE-2026-39821: golang.org/x/net/idna: failure to reject ASCII-only Punycode-encoded labels allows for validation bypass and privilege escalation (bsc#1266575).
- CVE-2026-39827, CVE-2026-39828, CVE-2026-39829, CVE-2026-39830, CVE-2026-39831, CVE-2026-39832, CVE-2026-39833, CVE-2026-39834, CVE-2026-39835, CVE-2026-42508, CVE-2026-46595, CVE-2026-46597, CVE-2026-46598:
golang.org/x/crypto/ssh: multiple issues in `x/crypto/ssh` (bsc#1266151).
- CVE-2026-46600: parsing of invalid SVCB or HTTPS RR when the size of a parameter value overflows the message buffer can lead to panic (bsc#1273606).
- CVE-2026-56852: improper handling of truncated/invalid UTF-8 input can lead to an infinite loop (bsc#1272011).

Other updates and bugfixes:

- Fix the release manifests' image references (bsc#1272604).
- Add a `libguestfs-tools` subpackage.
- Build with Go >= 1.25 (required by `golang.org/x/net` 0.55).
- Version 1.8.4:
* node-labeller: use new `libvirt` flags for full feature expansion.
* Fix gRPC connection leak in `GetLauncherClient`; clean up ghost launcher record on connection setup failure.
* api: validate `VMI VSOCK CID` and checksum status fields as `uint32`.
* virt-operator: refine canary flow to fully support out-of-band changes.
* New `virt-api`/`virt-handler`/`virt-operator` ready and down metrics, alerts and recording rules.
- Refresh `disks-images-provider.yaml` to the v1.8.4 image tag.

Tenable has extracted the preceding description block directly from the SUSE security advisory.

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.

Solution

Update the affected packages.

See Also

https://bugzilla.suse.com/1262265

https://bugzilla.suse.com/1265736

https://bugzilla.suse.com/1266151

https://bugzilla.suse.com/1266575

https://bugzilla.suse.com/1267120

https://bugzilla.suse.com/1269093

https://bugzilla.suse.com/1272011

https://bugzilla.suse.com/1272604

https://bugzilla.suse.com/1272840

https://bugzilla.suse.com/1273606

https://www.suse.com/security/cve/CVE-2026-13201

https://www.suse.com/security/cve/CVE-2026-13622

https://www.suse.com/security/cve/CVE-2026-25680

https://www.suse.com/security/cve/CVE-2026-25681

https://www.suse.com/security/cve/CVE-2026-27136

https://www.suse.com/security/cve/CVE-2026-33814

https://www.suse.com/security/cve/CVE-2026-35469

https://www.suse.com/security/cve/CVE-2026-39821

https://www.suse.com/security/cve/CVE-2026-39827

https://www.suse.com/security/cve/CVE-2026-39828

https://www.suse.com/security/cve/CVE-2026-39829

https://www.suse.com/security/cve/CVE-2026-39830

https://www.suse.com/security/cve/CVE-2026-39831

https://www.suse.com/security/cve/CVE-2026-39832

https://www.suse.com/security/cve/CVE-2026-39833

https://www.suse.com/security/cve/CVE-2026-39834

https://www.suse.com/security/cve/CVE-2026-39835

https://www.suse.com/security/cve/CVE-2026-42502

https://www.suse.com/security/cve/CVE-2026-42506

https://www.suse.com/security/cve/CVE-2026-42508

https://www.suse.com/security/cve/CVE-2026-46595

https://www.suse.com/security/cve/CVE-2026-46597

https://www.suse.com/security/cve/CVE-2026-46598

https://www.suse.com/security/cve/CVE-2026-46600

https://www.suse.com/security/cve/CVE-2026-56852

Plugin Details

Severity: High

ID: 338629

File Name: openSUSE-2026-21590-1.nasl

Version: 1.1

Type: Local

Agent: unix

Published: 8/21/2026

Updated: 8/21/2026

Supported Sensors: Frictionless Assessment AWS, Frictionless Assessment Azure, Frictionless Assessment Agent, Nessus Agent, Continuous Assessment, Tenable Cloud Security, Tenable Self-Hosted Container Security, Nessus

Risk Information

VPR

Risk Factor: Medium

Score: 5.9

Percentile: 96.55

CVSS v2

Risk Factor: High

Base Score: 7.8

Temporal Score: 5.8

Vector: CVSS2#AV:N/AC:L/Au:N/C:N/I:N/A:C

CVSS Score Source: CVE-2026-33814

CVSS v3

Risk Factor: High

Base Score: 7.5

Temporal Score: 6.5

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

CVSS v4

Risk Factor: High

Base Score: 8.7

Threat Score: 6.6

Threat Vector: CVSS:4.0/E:U

Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N

CVSS Score Source: CVE-2026-35469

Vulnerability Information

CPE: cpe:/o:novell:opensuse:16.0, p-cpe:/a:novell:opensuse:kubevirt1.8-container-disk, p-cpe:/a:novell:opensuse:kubevirt1.8-libguestfs-tools, p-cpe:/a:novell:opensuse:kubevirt1.8-pr-helper-conf, p-cpe:/a:novell:opensuse:kubevirt1.8-sidecar-shim, p-cpe:/a:novell:opensuse:kubevirt1.8-tests, p-cpe:/a:novell:opensuse:kubevirt1.8-virt-api, p-cpe:/a:novell:opensuse:kubevirt1.8-virt-controller, p-cpe:/a:novell:opensuse:kubevirt1.8-virt-exportproxy, p-cpe:/a:novell:opensuse:kubevirt1.8-virt-exportserver, p-cpe:/a:novell:opensuse:kubevirt1.8-virt-handler, p-cpe:/a:novell:opensuse:kubevirt1.8-virt-launcher, p-cpe:/a:novell:opensuse:kubevirt1.8-virt-operator, p-cpe:/a:novell:opensuse:kubevirt1.8-virt-synchronization-controller, p-cpe:/a:novell:opensuse:kubevirt1.8-virtctl

Required KB Items: Host/local_checks_enabled, Host/cpu, Host/SuSE/release, Host/SuSE/rpm-list

Exploit Ease: No known exploits are available

Patch Publication Date: 8/18/2026

Vulnerability Publication Date: 4/16/2026

Reference Information

CVE: CVE-2026-13201, CVE-2026-13622, CVE-2026-25680, CVE-2026-25681, CVE-2026-27136, CVE-2026-33814, CVE-2026-35469, CVE-2026-39821, CVE-2026-39827, CVE-2026-39828, CVE-2026-39829, CVE-2026-39830, CVE-2026-39831, CVE-2026-39832, CVE-2026-39833, CVE-2026-39834, CVE-2026-39835, CVE-2026-42502, CVE-2026-42506, CVE-2026-42508, CVE-2026-46595, CVE-2026-46597, CVE-2026-46598, CVE-2026-46600, CVE-2026-56852