Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-7374

Опубликовано: 26 мая 2026
Источник: redhat
CVSS3: 9.9
EPSS Низкий

Описание

A flaw was found in KubeVirt's virt-handler component. This vulnerability allows an authenticated OpenShift user with edit permissions in a single namespace to exploit improper symlink validation when connecting to virtual machine console sockets. By replacing the console socket with a symlink to the host's container runtime (CRI-O) socket, an attacker can hijack virt-handler's privileged connection. This enables the attacker to access any Unix socket on the host, potentially leading to full control of the node and the entire cluster.

Отчет

This is an Important privilege escalation flaw in KubeVirt's virt-handler component. An authenticated OpenShift user with edit permissions in a single namespace can exploit improper symlink validation to hijack virt-handler's privileged connection. This allows access to any Unix socket on the host, leading to potential full control of the node and the entire cluster.

Меры по смягчению последствий

Update cluster RBAC to not allow exec into virt-launcher pods.

Дополнительная информация

Статус:

Important
Дефект:
CWE-59
https://bugzilla.redhat.com/show_bug.cgi?id=2463728kubevirt: KubeVirt virt-handler: Privilege escalation and node compromise via symlink following vulnerability

EPSS

Процентиль: 45%
0.00596
Низкий

9.9 Critical

CVSS3

Связанные уязвимости

CVSS3: 9.9
nvd
2 месяца назад

A flaw was found in KubeVirt's virt-handler component. This vulnerability allows an authenticated OpenShift user with edit permissions in a single namespace to exploit improper symlink validation when connecting to virtual machine console sockets. By replacing the console socket with a symlink to the host's container runtime (CRI-O) socket, an attacker can hijack virt-handler's privileged connection. This enables the attacker to access any Unix socket on the host, potentially leading to full control of the node and the entire cluster.

CVSS3: 9.9
msrc
2 месяца назад

Kubevirt: kubevirt virt-handler: privilege escalation and node compromise via symlink following vulnerability

suse-cvrf
2 месяца назад

Security update for kubevirt

CVSS3: 9.9
github
2 месяца назад

KubeVirt has a Link Following vulnerability

suse-cvrf
около 2 месяцев назад

Security update for kubevirt-1.6

EPSS

Процентиль: 45%
0.00596
Низкий

9.9 Critical

CVSS3