SUSE-SU-2026:3955-1: important: Security update for kubevirt, virt-pr-helper-container
SLE-SECURITY-UPDATES
null at suse.de
Thu Sep 3 12:31:01 UTC 2026
# Security update for kubevirt, virt-pr-helper-container
Announcement ID: SUSE-SU-2026:3955-1
Release Date: 2026-09-03T07:54:42Z
Rating: important
References:
* bsc#1276520
Affected Products:
* Containers Module 15-SP7
* SUSE Linux Enterprise Real Time 15 SP7
* SUSE Linux Enterprise Server 15 SP7
* SUSE Linux Enterprise Server for SAP Applications 15 SP7
An update that has one security fix can now be installed.
## Description:
This update for kubevirt, virt-pr-helper-container fixes the following issues:
Changes in kubevirt:
* Package the persistent-reservation helper's entrypoint script (bsc#1276520):
virt-operator runs the pr-helper container with the command /entrypoint.sh,
which symlinks the multipath socket into place and then execs qemu-pr-
helper. Only multipath.conf was installed, so the container could not start
and persistent reservation was unavailable. The script is upstream in
cmd/pr-helper/entrypoint.sh.
* Re-vendor google.golang.org/grpc v1.79.3 -> v1.82.1: GO-2026-6061 (GHSA-
hrxh-6v49-42gf, no CVE id assigned yet) fixes flaws in the xDS RBAC
authorization engine, which kubevirt does not vendor, and in the HTTP/2
transport server implementation (internal/transport), which kubevirt vendors
and uses for the virt-handler and virt-launcher gRPC servers. Ride-along
minimum-version bumps: google.golang.org/protobuf v1.36.10 -> v1.36.11,
google.golang.org/genproto/googleapis/rpc to the 20260414 snapshot.
* Run the Go unit tests of the pkg/ tree in %check (new bcond "check", default
on; --without check disables). Two packages are excluded with reasons in the
spec: the fuzz-seed suite and the virtctl root test fail identically on the
unpatched source tree.
* Sync all remaining fixes from the upstream release-1.7 branch head (upstream
has cut no 1.7.5 tag since v1.7.4, 2026-06-01):
* data race on the shared error variable in the abortChangeVMIs goroutine
* virt-operator error paths: fix a nil-pointer dereference on shadowed
variables and log resource names instead of full object dumps
* add the --with-kubevirt-control-plane-label flag to csv-generator and
manifest-templator
* virtctl image-upload retried with the same upload token after it expired, so
every remaining retry failed with 401; refresh the token between retries
* virsh domcapabilities omitted features implicitly enabled by the base CPU
model, leaving host-model-required-features node labels incomplete
* validate existence and CSI support of PVC volumes before volume migration;
incomplete MigratedVolumes entries silently broke the migration flow (file
instead of block disk on the target)
* test companion of the PVC validation fix
* a migration whose target pod dies after proxy setup but before QEMU
migration starts was never finalized, leaving the VMI migration state
pending forever
* set terminationGracePeriodSeconds 10 in the testing disks-images-provider
manifest so pod teardown does not wait out a 30s grace period blocked on a
foreground sleep
* fix the Cirros boot order test on IPv6-only clusters
* remove e2e tests that are redundant with unit coverage
* the migration controller garbage-collected migration objects but left their
old virt-launcher pods behind; clean both up together
* virt-launcher stopped processing libvirt events while a domain was paused
due to an I/O error; lifecycle events (migration started/ finished on the
target), agent-sourced status (interfaces, OS info, fsFreeze) were dropped,
and the domain state update itself only propagated if GetDiskErrors returned
a faulty disk, leaving the VMI status stale until unpause. Backport of
upstream commit 9f14a3450109 (PR#16778, released in v1.8.0), adapted to the
1.7 code base.
Changes in virt-pr-helper-container:
* Ship the pr-helper entrypoint script (bsc#1276520): virt-operator starts the
pr-helper container with the command /entrypoint.sh, which symlinks the
multipath socket into place and then execs qemu-pr-helper. The image
contained only the bare binary, so enabling the PersistentReservation
feature gate put every virt-handler pod into CrashLoopBackOff. Add
entrypoint.sh (verbatim upstream cmd/pr-helper/entrypoint.sh) and hand the
entrypoint to it.
## Patch Instructions:
To install this SUSE update use the SUSE recommended installation methods like
YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
* Containers Module 15-SP7
zypper in -t patch SUSE-SLE-Module-Containers-15-SP7-2026-3955=1
## Package List:
* Containers Module 15-SP7 (aarch64 x86_64)
* kubevirt-virtctl-1.7.4-150700.3.39.1
* kubevirt-virtctl-debuginfo-1.7.4-150700.3.39.1
* kubevirt-manifests-1.7.4-150700.3.39.1
## References:
* https://bugzilla.suse.com/show_bug.cgi?id=1276520
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <https://lists.suse.com/pipermail/sle-security-updates/attachments/20260903/6d54d0b7/attachment-0001.htm>
More information about the sle-security-updates
mailing list