Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

SUSE-SU-2026:3604-1

Опубликовано: 13 авг. 2026
Источник: suse-cvrf

Описание

Security update for kubevirt

This update for kubevirt fixes the following issue:

  • CVE-2026-13622: virt-handler migration proxy follows symlinks, allowing container escape to host (bsc#1272840).

Список пакетов

SUSE Linux Enterprise Module for Containers 15 SP7
kubevirt-manifests-1.7.4-150700.3.36.1
kubevirt-virtctl-1.7.4-150700.3.36.1

Описание

A symlink following vulnerability was found in KubeVirt's virt-handler migration proxy. During live migration, virt-handler dials Unix sockets inside the target virt-launcher pod via /proc/<pid>/root/ paths using net.Dial() without symlink protection. These socket paths reside in qemu-owned directories writable by the virt-launcher user. An attacker with namespace edit and pods/exec permissions can replace a migration proxy socket with a symlink to the host CRI-O socket. Because virt-handler runs as root in the host mount namespace, absolute symlink targets resolve against the host filesystem, and the bidirectional io.Copy proxy relays attacker-controlled bytes to the container runtime, enabling full node compromise.


Затронутые продукты
SUSE Linux Enterprise Module for Containers 15 SP7:kubevirt-manifests-1.7.4-150700.3.36.1
SUSE Linux Enterprise Module for Containers 15 SP7:kubevirt-virtctl-1.7.4-150700.3.36.1

Ссылки