Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2025-64435

Опубликовано: 07 нояб. 2025
Источник: redhat
CVSS3: 5.3
EPSS Низкий

Описание

KubeVirt is a virtual machine management add-on for Kubernetes. Prior to 1.7.0-beta.0, a logic flaw in the virt-controller allows an attacker to disrupt the control over a running VMI by creating a pod with the same labels as the legitimate virt-launcher pod associated with the VMI. This can mislead the virt-controller into associating the fake pod with the VMI, resulting in incorrect status updates and potentially causing a DoS (Denial-of-Service). This vulnerability is fixed in 1.7.0-beta.0.

A denial of service flaw has been discovered in KubeVirt. A logic flaw in the virt-controller allows an attacker to disrupt the control over a running VMI by creating a pod with the same labels as the legitimate virt-launcher pod associated with the VMI. This can mislead the virt-controller into associating the fake pod with the VMI, resulting in incorrect status updates and potentially causing a DoS (Denial-of-Service).

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat OpenShift Virtualization 4container-native-virtualization/kubemacpool-rhel9Fix deferred
Red Hat OpenShift Virtualization 4container-native-virtualization/kubevirt-tekton-tasks-create-datavolume-rhel9Fix deferred
Red Hat OpenShift Virtualization 4container-native-virtualization/kubevirt-tekton-tasks-disk-virt-customize-rhel9Fix deferred
Red Hat OpenShift Virtualization 4container-native-virtualization/mtq-controller-rhel9Fix deferred
Red Hat OpenShift Virtualization 4container-native-virtualization/mtq-lock-server-rhel9Fix deferred
Red Hat OpenShift Virtualization 4container-native-virtualization/mtq-operator-rhel9Fix deferred
Red Hat OpenShift Virtualization 4container-native-virtualization/ocp-virt-validation-checkup-rhel9Fix deferred
Red Hat OpenShift Virtualization 4container-native-virtualization/passt-network-binding-plugin-cni-rhel9Fix deferred
Red Hat OpenShift Virtualization 4container-native-virtualization/passt-network-binding-plugin-sidecar-rhel9Fix deferred
Red Hat OpenShift Virtualization 4container-native-virtualization/sidecar-shim-rhel9Fix deferred

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-703
https://bugzilla.redhat.com/show_bug.cgi?id=2413498kubevirt.io/kubevirt: KubeVirt VMI Denial-of-Service Using Pod Impersonation

EPSS

Процентиль: 24%
0.00081
Низкий

5.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.3
nvd
5 месяцев назад

KubeVirt is a virtual machine management add-on for Kubernetes. Prior to 1.7.0-beta.0, a logic flaw in the virt-controller allows an attacker to disrupt the control over a running VMI by creating a pod with the same labels as the legitimate virt-launcher pod associated with the VMI. This can mislead the virt-controller into associating the fake pod with the VMI, resulting in incorrect status updates and potentially causing a DoS (Denial-of-Service). This vulnerability is fixed in 1.7.0-beta.0.

CVSS3: 5.3
msrc
4 месяца назад

KubeVirt VMI Denial-of-Service (DoS) Using Pod Impersonation

CVSS3: 5.3
github
5 месяцев назад

KubeVirt VMI Denial-of-Service (DoS) Using Pod Impersonation

suse-cvrf
около 2 месяцев назад

Security update for kubevirt, virt-api-container, virt-controller-container, virt-exportproxy-container, virt-exportserver-container, virt-handler-container, virt-launcher-container, virt-libguestfs-tools-container, virt-operator-container, virt-pr-helper-container, virt-synchronization-controller-container

suse-cvrf
около 1 месяца назад

Security update for kubevirt

EPSS

Процентиль: 24%
0.00081
Низкий

5.3 Medium

CVSS3