<?xml version="1.0" encoding="UTF-8"?>
<cvrfdoc xmlns="http://www.icasi.org/CVRF/schema/cvrf/1.1" xmlns:cvrf="http://www.icasi.org/CVRF/schema/cvrf/1.1">
  <DocumentTitle xml:lang="en">kubevirt-container-disk-1.6.3-1.1 on GA media</DocumentTitle>
  <DocumentType>SUSE Patch</DocumentType>
  <DocumentPublisher Type="Vendor">
    <ContactDetails>security@suse.de</ContactDetails>
    <IssuingAuthority>SUSE Security Team</IssuingAuthority>
  </DocumentPublisher>
  <DocumentTracking>
    <Identification>
      <ID>openSUSE-SU-2025:15772-1</ID>
    </Identification>
    <Status>Final</Status>
    <Version>1</Version>
    <RevisionHistory>
      <Revision>
        <Number>1</Number>
        <Date>2025-11-26T00:00:00Z</Date>
        <Description>current</Description>
      </Revision>
    </RevisionHistory>
    <InitialReleaseDate>2025-11-26T00:00:00Z</InitialReleaseDate>
    <CurrentReleaseDate>2025-11-26T00:00:00Z</CurrentReleaseDate>
    <Generator>
      <Engine>cve-database/bin/generate-cvrf.pl</Engine>
      <Date>2017-02-24T01:00:00Z</Date>
    </Generator>
  </DocumentTracking>
  <DocumentNotes>
    <Note Title="Topic" Type="Summary" Ordinal="1" xml:lang="en">kubevirt-container-disk-1.6.3-1.1 on GA media</Note>
    <Note Title="Details" Type="General" Ordinal="2" xml:lang="en">These are all security issues fixed in the kubevirt-container-disk-1.6.3-1.1 package on the GA media of openSUSE Tumbleweed.</Note>
    <Note Title="Terms of Use" Type="Legal Disclaimer" Ordinal="3" xml:lang="en">The CVRF data is provided by SUSE under the Creative Commons License 4.0 with Attribution (CC-BY-4.0).</Note>
    <Note Title="Patchnames" Type="Details" Ordinal="4" xml:lang="en">openSUSE-Tumbleweed-2025-15772</Note>
  </DocumentNotes>
  <DocumentDistribution xml:lang="en">Copyright SUSE LLC under the Creative Commons License 4.0 with Attribution (CC-BY-4.0)</DocumentDistribution>
  <DocumentReferences>
    <Reference Type="Self">
      <URL>https://www.suse.com/support/security/rating/</URL>
      <Description>SUSE Security Ratings</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2025-22872/</URL>
      <Description>SUSE CVE CVE-2025-22872 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2025-64433/</URL>
      <Description>SUSE CVE CVE-2025-64433 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2025-64437/</URL>
      <Description>SUSE CVE CVE-2025-64437 page</Description>
    </Reference>
  </DocumentReferences>
  <ProductTree xmlns="http://www.icasi.org/CVRF/schema/prod/1.1">
    <Branch Type="Product Family" Name="openSUSE Tumbleweed">
      <Branch Type="Product Name" Name="openSUSE Tumbleweed">
        <FullProductName ProductID="openSUSE Tumbleweed" CPE="cpe:/o:opensuse:tumbleweed">openSUSE Tumbleweed</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Version" Name="kubevirt-container-disk-1.6.3-1.1">
      <FullProductName ProductID="kubevirt-container-disk-1.6.3-1.1">kubevirt-container-disk-1.6.3-1.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="kubevirt-manifests-1.6.3-1.1">
      <FullProductName ProductID="kubevirt-manifests-1.6.3-1.1">kubevirt-manifests-1.6.3-1.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="kubevirt-pr-helper-conf-1.6.3-1.1">
      <FullProductName ProductID="kubevirt-pr-helper-conf-1.6.3-1.1">kubevirt-pr-helper-conf-1.6.3-1.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="kubevirt-sidecar-shim-1.6.3-1.1">
      <FullProductName ProductID="kubevirt-sidecar-shim-1.6.3-1.1">kubevirt-sidecar-shim-1.6.3-1.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="kubevirt-tests-1.6.3-1.1">
      <FullProductName ProductID="kubevirt-tests-1.6.3-1.1">kubevirt-tests-1.6.3-1.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="kubevirt-virt-api-1.6.3-1.1">
      <FullProductName ProductID="kubevirt-virt-api-1.6.3-1.1">kubevirt-virt-api-1.6.3-1.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="kubevirt-virt-controller-1.6.3-1.1">
      <FullProductName ProductID="kubevirt-virt-controller-1.6.3-1.1">kubevirt-virt-controller-1.6.3-1.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="kubevirt-virt-exportproxy-1.6.3-1.1">
      <FullProductName ProductID="kubevirt-virt-exportproxy-1.6.3-1.1">kubevirt-virt-exportproxy-1.6.3-1.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="kubevirt-virt-exportserver-1.6.3-1.1">
      <FullProductName ProductID="kubevirt-virt-exportserver-1.6.3-1.1">kubevirt-virt-exportserver-1.6.3-1.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="kubevirt-virt-handler-1.6.3-1.1">
      <FullProductName ProductID="kubevirt-virt-handler-1.6.3-1.1">kubevirt-virt-handler-1.6.3-1.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="kubevirt-virt-launcher-1.6.3-1.1">
      <FullProductName ProductID="kubevirt-virt-launcher-1.6.3-1.1">kubevirt-virt-launcher-1.6.3-1.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="kubevirt-virt-operator-1.6.3-1.1">
      <FullProductName ProductID="kubevirt-virt-operator-1.6.3-1.1">kubevirt-virt-operator-1.6.3-1.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="kubevirt-virtctl-1.6.3-1.1">
      <FullProductName ProductID="kubevirt-virtctl-1.6.3-1.1">kubevirt-virtctl-1.6.3-1.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="obs-service-kubevirt_containers_meta-1.6.3-1.1">
      <FullProductName ProductID="obs-service-kubevirt_containers_meta-1.6.3-1.1">obs-service-kubevirt_containers_meta-1.6.3-1.1</FullProductName>
    </Branch>
    <Relationship ProductReference="kubevirt-container-disk-1.6.3-1.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:kubevirt-container-disk-1.6.3-1.1">kubevirt-container-disk-1.6.3-1.1 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="kubevirt-manifests-1.6.3-1.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:kubevirt-manifests-1.6.3-1.1">kubevirt-manifests-1.6.3-1.1 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="kubevirt-pr-helper-conf-1.6.3-1.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:kubevirt-pr-helper-conf-1.6.3-1.1">kubevirt-pr-helper-conf-1.6.3-1.1 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="kubevirt-sidecar-shim-1.6.3-1.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:kubevirt-sidecar-shim-1.6.3-1.1">kubevirt-sidecar-shim-1.6.3-1.1 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="kubevirt-tests-1.6.3-1.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:kubevirt-tests-1.6.3-1.1">kubevirt-tests-1.6.3-1.1 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="kubevirt-virt-api-1.6.3-1.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:kubevirt-virt-api-1.6.3-1.1">kubevirt-virt-api-1.6.3-1.1 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="kubevirt-virt-controller-1.6.3-1.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:kubevirt-virt-controller-1.6.3-1.1">kubevirt-virt-controller-1.6.3-1.1 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="kubevirt-virt-exportproxy-1.6.3-1.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:kubevirt-virt-exportproxy-1.6.3-1.1">kubevirt-virt-exportproxy-1.6.3-1.1 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="kubevirt-virt-exportserver-1.6.3-1.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:kubevirt-virt-exportserver-1.6.3-1.1">kubevirt-virt-exportserver-1.6.3-1.1 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="kubevirt-virt-handler-1.6.3-1.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:kubevirt-virt-handler-1.6.3-1.1">kubevirt-virt-handler-1.6.3-1.1 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="kubevirt-virt-launcher-1.6.3-1.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:kubevirt-virt-launcher-1.6.3-1.1">kubevirt-virt-launcher-1.6.3-1.1 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="kubevirt-virt-operator-1.6.3-1.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:kubevirt-virt-operator-1.6.3-1.1">kubevirt-virt-operator-1.6.3-1.1 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="kubevirt-virtctl-1.6.3-1.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:kubevirt-virtctl-1.6.3-1.1">kubevirt-virtctl-1.6.3-1.1 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="obs-service-kubevirt_containers_meta-1.6.3-1.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:obs-service-kubevirt_containers_meta-1.6.3-1.1">obs-service-kubevirt_containers_meta-1.6.3-1.1 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
  </ProductTree>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="1">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">The tokenizer incorrectly interprets tags with unquoted attribute values that end with a solidus character (/) as self-closing. When directly using Tokenizer, this can result in such tags incorrectly being marked as self-closing, and when using the Parse functions, this can result in content following such tags as being placed in the wrong scope during DOM construction, but only when tags are in foreign content (e.g. &lt;math&gt;, &lt;svg&gt;, etc contexts).</Note>
    </Notes>
    <CVE>CVE-2025-22872</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Tumbleweed:kubevirt-container-disk-1.6.3-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:kubevirt-manifests-1.6.3-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:kubevirt-pr-helper-conf-1.6.3-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:kubevirt-sidecar-shim-1.6.3-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:kubevirt-tests-1.6.3-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:kubevirt-virt-api-1.6.3-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:kubevirt-virt-controller-1.6.3-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:kubevirt-virt-exportproxy-1.6.3-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:kubevirt-virt-exportserver-1.6.3-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:kubevirt-virt-handler-1.6.3-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:kubevirt-virt-launcher-1.6.3-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:kubevirt-virt-operator-1.6.3-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:kubevirt-virtctl-1.6.3-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:obs-service-kubevirt_containers_meta-1.6.3-1.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL/>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2025-22872.html</URL>
        <Description>CVE-2025-22872</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1241710</URL>
        <Description>SUSE Bug 1241710</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="2">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">KubeVirt is a virtual machine management add-on for Kubernetes. Prior to 1.5.3 and 1.6.1, a vulnerability was discovered that allows a VM to read arbitrary files from the virt-launcher pod's file system. This issue stems from improper symlink handling when mounting PVC disks into a VM. Specifically, if a malicious user has full or partial control over the contents of a PVC, they can create a symbolic link that points to a file within the virt-launcher pod's file system. Since libvirt can treat regular files as block devices, any file on the pod's file system that is symlinked in this way can be mounted into the VM and subsequently read. Although a security mechanism exists where VMs are executed as an unprivileged user with UID 107 inside the virt-launcher container, limiting the scope of accessible resources, this restriction is bypassed due to a second vulnerability. The latter causes the ownership of any file intended for mounting to be changed to the unprivileged user with UID 107 prior to mounting. As a result, an attacker can gain access to and read arbitrary files located within the virt-launcher pod's file system or on a mounted PVC from within the guest VM. This vulnerability is fixed in 1.5.3 and 1.6.1.</Note>
    </Notes>
    <CVE>CVE-2025-64433</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Tumbleweed:kubevirt-container-disk-1.6.3-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:kubevirt-manifests-1.6.3-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:kubevirt-pr-helper-conf-1.6.3-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:kubevirt-sidecar-shim-1.6.3-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:kubevirt-tests-1.6.3-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:kubevirt-virt-api-1.6.3-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:kubevirt-virt-controller-1.6.3-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:kubevirt-virt-exportproxy-1.6.3-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:kubevirt-virt-exportserver-1.6.3-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:kubevirt-virt-handler-1.6.3-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:kubevirt-virt-launcher-1.6.3-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:kubevirt-virt-operator-1.6.3-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:kubevirt-virtctl-1.6.3-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:obs-service-kubevirt_containers_meta-1.6.3-1.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL/>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2025-64433.html</URL>
        <Description>CVE-2025-64433</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1253185</URL>
        <Description>SUSE Bug 1253185</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="3">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">KubeVirt is a virtual machine management add-on for Kubernetes. In versions before 1.5.3 and 1.6.1, the virt-handler does not verify whether the launcher-sock is a symlink or a regular file. This oversight can be exploited, for example, to change the ownership of arbitrary files on the host node to the unprivileged user with UID 107 (the same user used by virt-launcher) thus, compromising the CIA (Confidentiality, Integrity and Availability) of data on the host. To successfully exploit this vulnerability, an attacker should be in control of the file system of the virt-launcher pod. This vulnerability is fixed in 1.5.3 and 1.6.1.</Note>
    </Notes>
    <CVE>CVE-2025-64437</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Tumbleweed:kubevirt-container-disk-1.6.3-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:kubevirt-manifests-1.6.3-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:kubevirt-pr-helper-conf-1.6.3-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:kubevirt-sidecar-shim-1.6.3-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:kubevirt-tests-1.6.3-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:kubevirt-virt-api-1.6.3-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:kubevirt-virt-controller-1.6.3-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:kubevirt-virt-exportproxy-1.6.3-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:kubevirt-virt-exportserver-1.6.3-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:kubevirt-virt-handler-1.6.3-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:kubevirt-virt-launcher-1.6.3-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:kubevirt-virt-operator-1.6.3-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:kubevirt-virtctl-1.6.3-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:obs-service-kubevirt_containers_meta-1.6.3-1.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL/>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2025-64437.html</URL>
        <Description>CVE-2025-64437</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1253194</URL>
        <Description>SUSE Bug 1253194</Description>
      </Reference>
    </References>
  </Vulnerability>
</cvrfdoc>
