Alerts This Week
Warning Icon 1 717
Alerts This Week
Warning Icon 1 717

SUSE: kubevirt Important Security Fix Multiple Issues 2025:4330-1

suse
Calendar Grey December 9, 2025
Dist Suse Esm H88
SUSE updates for kubevirt and related containers address multiple security flaws affecting container operations.
* bsc#1241772 * bsc#1250683 * bsc#1253181 * bsc#1253185 * bsc#1253186

Summary

## This update for kubevirt, virt-api-container, virt-controller-container, virt- exportproxy-container, virt-exportserver-container, virt-handler-container, virt-launcher-container, virt-libguestfs-tools-container, virt-operator- container, virt-pr-helper-container fixes the following issues: Updated kubevirt to version 1.6.3: * CVE-2025-22872: Fixed incorrect interpretation of tags leading content to be placed wrong scope during DOM construction in golang.org/x/net/html (bsc#1241772) * CVE-2025-64432: Fixed bypass of RBAC controls due to incorrect validation of certain fields in the client TLS certificate (bsc#1253181) * CVE-2025-64433: Fixed arbitrary files read via improper symlink handling (bsc#1253185)

References

* bsc#1241772

* bsc#1250683

* bsc#1253181

* bsc#1253185

* bsc#1253186

* bsc#1253194

* bsc#1253384

* bsc#1253748

Cross-

* CVE-2025-22872

* CVE-2025-64324

* CVE-2025-64432

* CVE-2025-64433

* CVE-2025-64434

* CVE-2025-64437

CVSS scores:

* CVE-2025-22872 ( SUSE ): 6.3

CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:L/SC:L/SI:L/SA:L

* CVE-2025-22872 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:L

* CVE-2025-22872 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:L

* CVE-2025-64324 ( SUSE ): 8.5

CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

* CVE-2025-64324 ( SUSE ): 7.7 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2025:4330-1
Release Date: 2025-12-09T11:34:00Z
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here