Alerts This Week
Warning Icon 1 474
Alerts This Week
Warning Icon 1 474

SUSE Kubevirt Important Update Fixing Privilege Escalation Vulnerabilities

suse
Calendar Grey June 15, 2026
Dist Suse Esm H88
Critical SUSE security update addresses seven vulnerabilities in kubevirt, ensuring enhanced security for systems.
An update that solves seven vulnerabilities can now be installed.

Summary

## This update for kubevirt fixes the following issues: Update to version 1.7.4, fixes various go embedded security issues: * CVE-2025-47911: golang.org/x/net/html: various algorithms with quadratic complexity when parsing HTML documents (bsc#1251420). * CVE-2025-47913: golang.org/x/crypto/ssh/agent: client process termination when receiving an unexpected message type in response to a key listing or signing request (bsc#1253559). * CVE-2025-47914: golang.org/x/crypto/ssh/agent: non validated message size can cause a panic due to an out of bounds read (bsc#1254014). * CVE-2025-58181: golang.org/x/crypto/ssh: invalidated number of mechanisms can cause unbounded memory consumption (bsc#1253935). * CVE-2025-58190: golang.org/x/net/html: excessive memory consumption by

References

* bsc#1251420

* bsc#1251615

* bsc#1253559

* bsc#1253935

* bsc#1254014

* bsc#1260234

* bsc#1265467

Cross-

* CVE-2025-47911

* CVE-2025-47913

* CVE-2025-47914

* CVE-2025-58181

* CVE-2025-58190

* CVE-2026-33186

* CVE-2026-7374

CVSS scores:

* CVE-2025-47911 ( SUSE ): 6.9

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N

* CVE-2025-47911 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L

* CVE-2025-47911 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L

* CVE-2025-47911 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L

* CVE-2025-47913 ( SUSE ): 8.7

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N

* CVE-2025-47913 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Severity
critical
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2026:2400-1
Release Date: 2026-06-15T15:34:14Z
Rating: critical

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here