< Back to situations

Monitor this situation.

[SITUATION] · [QUIET] · [TECHNOLOGY]

2 clusters · 8 sources · 6 days · First seen · Last updated

Red Hat and SUSE security vulnerability disclosures

Overview

Red Hat and SUSE have disclosed several critical security vulnerabilities affecting enterprise software and virtualization components.

Red Hat reported a high-severity privilege escalation flaw (CVE-2026-10090) in its Advanced Cluster Management for Kubernetes. The vulnerability, which carries a CVSS score of 9.9, allows users with limited permissions to potentially gain full cluster-admin status. Simultaneously, SUSE released patches for various vulnerabilities across its Linux and openSUSE distributions, addressing risks such as remote code execution and denial of service in components like the Linux kernel and OpenSSH.

Following these disclosures, SUSE identified a specific critical vulnerability (CVE-2026-25727) in the virtiofsd virtualization component. This flaw, rated with a CVSS score of 8.7, involves an error in the daemon’s date parser that can lead to stack exhaustion. The issue affects multiple operating systems, including openSUSE Leap 15.6 and several SUSE Linux Enterprise Server versions, necessitating updates to maintain the stability of virtualized infrastructures.

Entities

SUSE · Red Hat · Kubernetes · openSUSE · M-net

Timeline

  1. 13 days ago

    [TECHNOLOGY] 6 sources
    SUSE addresses critical CVE-2026-25727 vulnerability in virtiofsd

    A high-risk vulnerability (CVE-2026-25727) in the virtiofsd component affects SUSE and openSUSE systems, potentially causing stack exhaustion in virtualized environments.

  2. 18 days ago

    [TECHNOLOGY] 2 sources
    Red Hat and SUSE disclose critical security vulnerabilities and patches

    Red Hat disclosed a critical 9.9 CVSS privilege escalation flaw in its ACM for Kubernetes, while SUSE released security patches for the Linux kernel, Python, and other core components.

Sources

allgaeuer-wirtschaftsmagazin.de · arbeits-abc.de · borncity.com · countryrebel.com · linuxcompatible.org · niederlausitz-aktuell.de · powolania.klaretyni.pl · wirtschaftsinformatik-24.de