SUSE Virtualization v1.8.2 Release Notes

This release introduces several features, enhancements, and bug fixes that improve system quality and the overall user experience. The documentation is available at https://documentation.suse.com/cloudnative/virtualization/v1.8/en/introduction/overview.html.

Installation

SUSE Virtualization can be installed using the ISO image, a bootable USB drive, and PXE boot. For more information, see the Installation section of the documentation.

Upgrades

SUSE Virtualization only allows upgrades from supported versions. For more information about upgrade paths and procedures, see Upgrades.

When upgrading from v1.7 to v1.8, you may encounter an operating system image corruption issue if all of the following conditions are met:

  • SUSE Virtualization v1.4.1 or earlier was originally installed.

  • A separate data disk is used.

  • The cluster has been continually upgraded in place.

For more information, see issue #10687.

Security Fixes

This release addresses security vulnerabilities in the following underlying components:

  • Operating system (SUSE Linux Micro): The BaseOS image was updated with the latest SUSE security patches for the Linux kernel, resolving several use-after-free vulnerabilities that could allow privilege escalation (#11209). For more information, see CVE-2026-53359, CVE-2026-43499, and CVE-2026-46242.

  • etcd (RKE2): RKE2 was updated to include a patched etcd version that resolves a denial-of-service vulnerability in the etcd TLS listener (GHSA-6vch-q96h-7gc3). This vulnerability could exhaust server memory and render the control plane or cluster unavailable.

  • virt-handler (KubeVirt): The virt-handler service now strictly validates virtual machine console socket file targets to prevent improper symlink resolution. This prevents authenticated users with namespace edit permissions from replacing console sockets with symlinks to host container runtime sockets (such as CRI-O), which could allow attackers to hijack privileged host connections and gain full node or cluster control. For more information, see CVE-2026-7374.

Bug fixes

  • #11268 [backport v1.8] [BUG] ipxe boot of v1.8.x onwards fails on some broadcom nics

  • #11218 [backport v1.8] [BUG] Failed image cannot be deleted due to finalizer lock when a successful upload exists

  • #11173 [backport v1.8] restoring a VM backup to a different cluster is not working as described or intended

  • #11149 [backport v1.8] [BUG] The v171 to v180 upgrade is blocked by CDI ISO image downloading

  • #11131 [backport v1.8] [BUG] harvester-webhook SA token expiration with RKE2 CIS profile enabled.

  • #11152 [backport v1.8] [BUG] /v1/harvester/kubeconfig rejects external Rancher global admins

Known issues

  • #10687 [BUG] v1.7.x → v1.8.0 OS-swap leaves two p11-kit files all-NUL in /usr/share on ~1/3 of nodes; breaks every TLS user on that host (containerd, Longhorn engine-image, kubelet)

  • #10447 [BUG] After upgraded to three Nodes with witness role to v1.8.0-rc6, vm failed to migrate with error "Kubevirt not ready"

  • #10221 [BUG] Failed to migrate VM after eject the windows image from CDROM device

  • #10220 [BUG] Fail to enable rancher-logging after negative upgrade cases

Components

Component Version

Containerized Data Importer (CDI)

v1.64.0

Kube-OVN

v1.15.4

KubeVirt

v1.7.4

SUSE® Storage

v1.11.2

SUSE® Rancher Prime (embedded)

v2.14.3

SUSE® Rancher Prime: RKE2

v1.35.7+rke2r1

SUSE Linux Micro

6.2