Linuxsecurity Critical Denial of Service Vulnerabilities in openSUSE Kubernetes
Article Content
- •Critical denial of service vulnerabilities identified in openSUSE Kubernetes versions 1.23 to 1.28.
- •CVE-2026-33814 and CVE-2026-35469 are the primary vulnerabilities addressed in recent patches.
- •Administrators are urged to apply patches immediately to prevent potential service disruptions.
Recent updates for openSUSE Kubernetes have addressed significant denial of service vulnerabilities, specifically CVE-2026-33814 and CVE-2026-35469. CVE-2026-33814, published on May 7, 2026, involves an infinite loop in HTTP/2 transport when bad SETTINGS_MAX_FRAME_SIZE is provided. CVE-2026-35469, published on April 16, 2026, relates to memory amplification in SPDY frame parsing, leading to potential denial of service. Affected versions include Kubernetes 1.23 through 1.28, with patches available for various openSUSE and SUSE Linux Enterprise products. The vulnerabilities pose a risk of service disruption for users running these Kubernetes versions. Administrators are advised to apply the latest patches immediately to mitigate risks. The updates were released on June 10, 2026, and are deemed important by SUSE.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (10)
Following this threat?
Track OpenSUSE and CVE-2026-33814 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical WSO2 API Manager Vulnerability Under Active Exploitation A critical vulnerability (CVE-2026-5430) in WSO2 API Manager is being actively exploited, allowing unauthenticated attackers to forge admin tokens via JWT authentication bypass. This flaw, which has a CVSS score of 10.0, affects multiple WSO2 products including API Manager, Universal Gateway, Traffic Manager, and API…
Critical Linux Kernel Vulnerability CVE-2025-39682 Under Active Exploitation A critical vulnerability (CVE-2025-39682) in the Linux kernel allows remote code execution through mishandling of zero-length TLS records. This flaw affects kTLS-enabled hosts running vulnerable kernel versions, exposing them to attackers without authentication. CISA added this vulnerability to its Known Exploited…