This update for kubevirt-1.6, virt-api-container-1.6, virt-controller-container-1.6, virt-exportproxy-container-1.6, virt-exportserver-container-1.6, virt-handler-container-1.6, virt-launcher-container-1.6, virt-libguestfs-tools-container-1.6, virt-operator-container-1.6, virt-pr-helper-container-1.6, virt-synchronization-controller-container-1.6 fixes the following issues:
html.ParseFragment when processing specially
crafted input can lead to a denial of service (bsc#1251615).OpenAtNoFollow symlink following via /proc/self/fd allows
host file metadata modification (bsc#1269093).SETTINGS_MAX_FRAME_SIZE
can lead to an infinite loop and a denial of service (bsc#1265736).Other updates and bugfixes:
printf-style calls with non-constant format strings (cmd/virt-chroot, tests/) that fail go1.25's vet
(toolchain required by the x/net 0.55.0 re-vendor); rewritten with no behavior change.golang.org/x/net 0.55).