SUSE-SU-2026:3955-1: important: Security update for kubevirt, virt-pr-helper-container

SLE-UPDATES null at suse.de
Thu Sep 3 12:30:45 UTC 2026


# Security update for kubevirt, virt-pr-helper-container

Announcement ID: SUSE-SU-2026:3955-1  
Release Date: 2026-09-03T07:54:42Z  
Rating: important  
References:

  * bsc#1276520

  
Affected Products:

  * Containers Module 15-SP7
  * SUSE Linux Enterprise Real Time 15 SP7
  * SUSE Linux Enterprise Server 15 SP7
  * SUSE Linux Enterprise Server for SAP Applications 15 SP7

  
  
An update that has one security fix can now be installed.

## Description:

This update for kubevirt, virt-pr-helper-container fixes the following issues:

Changes in kubevirt:

  * Package the persistent-reservation helper's entrypoint script (bsc#1276520):
    virt-operator runs the pr-helper container with the command /entrypoint.sh,
    which symlinks the multipath socket into place and then execs qemu-pr-
    helper. Only multipath.conf was installed, so the container could not start
    and persistent reservation was unavailable. The script is upstream in
    cmd/pr-helper/entrypoint.sh.

  * Re-vendor google.golang.org/grpc v1.79.3 -> v1.82.1: GO-2026-6061 (GHSA-
    hrxh-6v49-42gf, no CVE id assigned yet) fixes flaws in the xDS RBAC
    authorization engine, which kubevirt does not vendor, and in the HTTP/2
    transport server implementation (internal/transport), which kubevirt vendors
    and uses for the virt-handler and virt-launcher gRPC servers. Ride-along
    minimum-version bumps: google.golang.org/protobuf v1.36.10 -> v1.36.11,
    google.golang.org/genproto/googleapis/rpc to the 20260414 snapshot.

  * Run the Go unit tests of the pkg/ tree in %check (new bcond "check", default
    on; --without check disables). Two packages are excluded with reasons in the
    spec: the fuzz-seed suite and the virtctl root test fail identically on the
    unpatched source tree.
  * Sync all remaining fixes from the upstream release-1.7 branch head (upstream
    has cut no 1.7.5 tag since v1.7.4, 2026-06-01):
  * data race on the shared error variable in the abortChangeVMIs goroutine
  * virt-operator error paths: fix a nil-pointer dereference on shadowed
    variables and log resource names instead of full object dumps
  * add the --with-kubevirt-control-plane-label flag to csv-generator and
    manifest-templator
  * virtctl image-upload retried with the same upload token after it expired, so
    every remaining retry failed with 401; refresh the token between retries
  * virsh domcapabilities omitted features implicitly enabled by the base CPU
    model, leaving host-model-required-features node labels incomplete
  * validate existence and CSI support of PVC volumes before volume migration;
    incomplete MigratedVolumes entries silently broke the migration flow (file
    instead of block disk on the target)
  * test companion of the PVC validation fix
  * a migration whose target pod dies after proxy setup but before QEMU
    migration starts was never finalized, leaving the VMI migration state
    pending forever
  * set terminationGracePeriodSeconds 10 in the testing disks-images-provider
    manifest so pod teardown does not wait out a 30s grace period blocked on a
    foreground sleep
  * fix the Cirros boot order test on IPv6-only clusters
  * remove e2e tests that are redundant with unit coverage
  * the migration controller garbage-collected migration objects but left their
    old virt-launcher pods behind; clean both up together

  * virt-launcher stopped processing libvirt events while a domain was paused
    due to an I/O error; lifecycle events (migration started/ finished on the
    target), agent-sourced status (interfaces, OS info, fsFreeze) were dropped,
    and the domain state update itself only propagated if GetDiskErrors returned
    a faulty disk, leaving the VMI status stale until unpause. Backport of
    upstream commit 9f14a3450109 (PR#16778, released in v1.8.0), adapted to the
    1.7 code base.

Changes in virt-pr-helper-container:

  * Ship the pr-helper entrypoint script (bsc#1276520): virt-operator starts the
    pr-helper container with the command /entrypoint.sh, which symlinks the
    multipath socket into place and then execs qemu-pr-helper. The image
    contained only the bare binary, so enabling the PersistentReservation
    feature gate put every virt-handler pod into CrashLoopBackOff. Add
    entrypoint.sh (verbatim upstream cmd/pr-helper/entrypoint.sh) and hand the
    entrypoint to it.

## Patch Instructions:

To install this SUSE update use the SUSE recommended installation methods like
YaST online_update or "zypper patch".  
Alternatively you can run the command listed for your product:

  * Containers Module 15-SP7  
    zypper in -t patch SUSE-SLE-Module-Containers-15-SP7-2026-3955=1

## Package List:

  * Containers Module 15-SP7 (aarch64 x86_64)
    * kubevirt-virtctl-1.7.4-150700.3.39.1
    * kubevirt-virtctl-debuginfo-1.7.4-150700.3.39.1
    * kubevirt-manifests-1.7.4-150700.3.39.1

## References:

  * https://bugzilla.suse.com/show_bug.cgi?id=1276520

-------------- next part --------------
An HTML attachment was scrubbed...
URL: <https://lists.suse.com/pipermail/sle-updates/attachments/20260903/11dd2e71/attachment-0001.htm>


More information about the sle-updates mailing list