Skip to content

Update default Cloud Hypervisor to v51.2 - #493

Open
MiguelsPizza wants to merge 1 commit into
kernel:mainfrom
MiguelsPizza:ch-v51.2
Open

MiguelsPizza wants to merge 1 commit into
kernel:mainfrom
MiguelsPizza:ch-v51.2

Conversation

@MiguelsPizza

@MiguelsPizza MiguelsPizza commented Oct 3, 2026 •

Copy link
Copy Markdown

Cloud Hypervisor v49.0 and v51.1 are affected by CVE-2026-45782 (GHSA-f47p-p25q-83rh). This embeds v51.2 and makes it the default for new instances (with live disk resize, like v51.1); v49.0 and v51.1 stay embedded so existing snapshots still restore.

Tests: go test ./lib/hypervisor/cloudhypervisor/ -run 'TestCapabilities|TestRegisteredCapabilities' and go test ./lib/vmm/ -run TestIsVersionSupported (Linux) pass; on main they fail with undefined: vmm.V51_2, and without the capabilities change TestCapabilitiesAdvertiseDiskResizeOnV51 fails for "version v51.2".


Note

Medium Risk
Changes the default VMM binary for new VMs (security fix) while keeping older binaries for restore; mis-versioned snapshots could still fail until migrated.

Overview
Adds Cloud Hypervisor v51.2 as an embedded VMM binary (x86_64 and aarch64) and sets DefaultVersion to v51.2 so new instances launch on the patched release. v49.0 and v51.1 remain embedded for snapshot restore during upgrades.

Download/CI paths (Makefile download-ch-binaries, ensure-ch-binaries, .github/workflows/test.yml) now fetch v51.2 alongside the older versions. CapabilitiesForVersion treats v51.2 like v51.1 for live disk resize; tests and lib/vmm README are updated accordingly.

Reviewed by Cursor Bugbot for commit 990f1c2. Bugbot is set up for automated code reviews on this repo. Configure here.

v49.0 and v51.1 are affected by CVE-2026-45782. Embed v51.2 and use it for
new instances; keep older versions so existing snapshots restore.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant