{"id":"SUSE-SU-2026:3955-1","summary":"Security update for kubevirt, virt-pr-helper-container","details":"This update for kubevirt, virt-pr-helper-container fixes the following issues:\n\nChanges in kubevirt:\n\n- Package the persistent-reservation helper's entrypoint script\n  (bsc#1276520):\n  virt-operator runs the pr-helper container with the command\n  /entrypoint.sh, which symlinks the multipath socket into place and\n  then execs qemu-pr-helper. Only multipath.conf was installed, so the\n  container could not start and persistent reservation was\n  unavailable. The script is upstream in cmd/pr-helper/entrypoint.sh.\n\n- Re-vendor google.golang.org/grpc v1.79.3 -\u003e v1.82.1: GO-2026-6061\n  (GHSA-hrxh-6v49-42gf, no CVE id assigned yet) fixes flaws in the\n  xDS RBAC authorization engine, which kubevirt does not vendor, and\n  in the HTTP/2 transport server implementation (internal/transport),\n  which kubevirt vendors and uses for the virt-handler and\n  virt-launcher gRPC servers. Ride-along minimum-version bumps:\n  google.golang.org/protobuf v1.36.10 -\u003e v1.36.11,\n  google.golang.org/genproto/googleapis/rpc to the 20260414 snapshot.\n- Run the Go unit tests of the pkg/ tree in %check (new bcond\n  'check', default on; --without check disables). Two packages are\n  excluded with reasons in the spec: the fuzz-seed suite and the\n  virtctl root test fail identically on the unpatched source tree.\n- Sync all remaining fixes from the upstream release-1.7 branch head\n  (upstream has cut no 1.7.5 tag since v1.7.4, 2026-06-01):\n  * data race on the shared error variable in the abortChangeVMIs\n    goroutine\n  * virt-operator error paths: fix a nil-pointer dereference on\n    shadowed variables and log resource names instead of full object\n    dumps\n  * add the --with-kubevirt-control-plane-label flag to csv-generator\n    and manifest-templator\n  * virtctl image-upload retried with the same upload token after it\n    expired, so every remaining retry failed with 401; refresh the\n    token between retries\n  * virsh domcapabilities omitted features implicitly enabled by the\n    base CPU model, leaving host-model-required-features node labels\n    incomplete\n  * validate existence and CSI support of PVC volumes before volume\n    migration; incomplete MigratedVolumes entries silently broke the\n    migration flow (file instead of block disk on the target)\n  * test companion of the PVC validation fix\n  * a migration whose target pod dies after proxy setup but before\n    QEMU migration starts was never finalized, leaving the VMI\n    migration state pending forever\n  * set terminationGracePeriodSeconds 10 in the testing\n    disks-images-provider manifest so pod teardown does not wait out\n    a 30s grace period blocked on a foreground sleep\n  * fix the Cirros boot order test on IPv6-only clusters\n  * remove e2e tests that are redundant with unit coverage\n  * the migration controller garbage-collected migration objects but\n    left their old virt-launcher pods behind; clean both up together\n\n- virt-launcher stopped processing libvirt events while a domain was\n  paused due to an I/O error; lifecycle events (migration started/\n  finished on the target), agent-sourced status (interfaces, OS info,\n  fsFreeze) were dropped, and the domain state update itself only\n  propagated if GetDiskErrors returned a faulty disk, leaving the VMI\n  status stale until unpause. Backport of upstream commit 9f14a3450109\n  (PR#16778, released in v1.8.0), adapted to the 1.7 code base.\n\nChanges in virt-pr-helper-container:\n\n- Ship the pr-helper entrypoint script (bsc#1276520):\n  virt-operator starts the pr-helper container with the command\n  /entrypoint.sh, which symlinks the multipath socket into place and\n  then execs qemu-pr-helper. The image contained only the bare binary,\n  so enabling the PersistentReservation feature gate put every\n  virt-handler pod into CrashLoopBackOff. Add entrypoint.sh (verbatim\n  upstream cmd/pr-helper/entrypoint.sh) and hand the entrypoint to it.\n","modified":"2026-09-10T18:23:22.469411873Z","published":"2026-09-03T07:54:31Z","references":[{"type":"ADVISORY","url":"https://www.suse.com/support/update/announcement/2026/suse-su-20263955-1/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1276520"}],"affected":[{"package":{"name":"kubevirt","ecosystem":"SUSE:Linux Enterprise Module for Containers 15 SP7","purl":"pkg:rpm/suse/kubevirt&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Containers%2015%20SP7"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.7.4-150700.3.39.1"}]}],"ecosystem_specific":{"binaries":[{"kubevirt-manifests":"1.7.4-150700.3.39.1","kubevirt-virtctl":"1.7.4-150700.3.39.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:3955-1.json"}}],"schema_version":"1.9.0"}