gpp_maybe
Security update for kubevirt, virt-pr-helper-container
SUSE-SLE-Module-Containers-15-SP7-2026-3955
This update for kubevirt, virt-pr-helper-container fixes the following issues: Changes in kubevirt: - Package the persistent-reservation helper's entrypoint script (bsc#1276520): virt-operator runs the pr-helper container with the command /entrypoint.sh, which symlinks the multipath socket into place and then execs qemu-pr-helper. Only multipath.conf was installed, so the container could not start and persistent reservation was unavailable. The script is upstream in cmd/pr-helper/entrypoint.sh. - Re-vendor google.golang.org/grpc v1.79.3 -> v1.82.1: GO-2026-6061 (GHSA-hrxh-6v49-42gf, no CVE id assigned yet) fixes flaws in the xDS RBAC authorization engine, which kubevirt does not vendor, and in the HTTP/2 transport server implementation (internal/transport), which kubevirt vendors and uses for the virt-handler and virt-launcher gRPC servers. Ride-along minimum-version bumps: google.golang.org/protobuf v1.36.10 -> v1.36.11, google.golang.org/genproto/googleapis/rpc to the 20260414 snapshot. - Run the Go unit tests of the pkg/ tree in %check (new bcond "check", default on; --without check disables). Two packages are excluded with reasons in the spec: the fuzz-seed suite and the virtctl root test fail identically on the unpatched source tree. - Sync all remaining fixes from the upstream release-1.7 branch head (upstream has cut no 1.7.5 tag since v1.7.4, 2026-06-01): * data race on the shared error variable in the abortChangeVMIs goroutine * virt-operator error paths: fix a nil-pointer dereference on shadowed variables and log resource names instead of full object dumps * add the --with-kubevirt-control-plane-label flag to csv-generator and manifest-templator * virtctl image-upload retried with the same upload token after it expired, so every remaining retry failed with 401; refresh the token between retries * virsh domcapabilities omitted features implicitly enabled by the base CPU model, leaving host-model-required-features node labels incomplete * validate existence and CSI support of PVC volumes before volume migration; incomplete MigratedVolumes entries silently broke the migration flow (file instead of block disk on the target) * test companion of the PVC validation fix * a migration whose target pod dies after proxy setup but before QEMU migration starts was never finalized, leaving the VMI migration state pending forever * set terminationGracePeriodSeconds 10 in the testing disks-images-provider manifest so pod teardown does not wait out a 30s grace period blocked on a foreground sleep * fix the Cirros boot order test on IPv6-only clusters * remove e2e tests that are redundant with unit coverage * the migration controller garbage-collected migration objects but left their old virt-launcher pods behind; clean both up together - virt-launcher stopped processing libvirt events while a domain was paused due to an I/O error; lifecycle events (migration started/ finished on the target), agent-sourced status (interfaces, OS info, fsFreeze) were dropped, and the domain state update itself only propagated if GetDiskErrors returned a faulty disk, leaving the VMI status stale until unpause. Backport of upstream commit 9f14a3450109 (PR#16778, released in v1.8.0), adapted to the 1.7 code base. Changes in virt-pr-helper-container: - Ship the pr-helper entrypoint script (bsc#1276520): virt-operator starts the pr-helper container with the command /entrypoint.sh, which symlinks the multipath socket into place and then execs qemu-pr-helper. The image contained only the bare binary, so enabling the PersistentReservation feature gate put every virt-handler pod into CrashLoopBackOff. Add entrypoint.sh (verbatim upstream cmd/pr-helper/entrypoint.sh) and hand the entrypoint to it.
-
Release DateSep 3 2026
-
References
-
Typesecurity
-
Severityimportant
cloud_download Downloads
Containers Module 15.7 aarch64
-
Packageskubevirt
Container native virtualizationkubevirt-manifests1.7.4-150700.3.39.1 lock src
YAML manifests used to install kubevirtkubevirt-virtctl1.7.4-150700.3.39.1 lock rpm
Client for managing kubevirt1.7.4-150700.3.39.1 lock rpm
Containers Module 15.7 x86_64
-
Packageskubevirt
Container native virtualizationkubevirt-manifests1.7.4-150700.3.39.1 lock src
YAML manifests used to install kubevirtkubevirt-virtctl1.7.4-150700.3.39.1 lock rpm
Client for managing kubevirt1.7.4-150700.3.39.1 lock rpm