Количество 7
Количество 7
GHSA-7jcp-v9w4-wjmg
KubeVirt has a Link Following vulnerability
CVE-2026-7374
A flaw was found in KubeVirt's virt-handler component. This vulnerability allows an authenticated OpenShift user with edit permissions in a single namespace to exploit improper symlink validation when connecting to virtual machine console sockets. By replacing the console socket with a symlink to the host's container runtime (CRI-O) socket, an attacker can hijack virt-handler's privileged connection. This enables the attacker to access any Unix socket on the host, potentially leading to full control of the node and the entire cluster.
CVE-2026-7374
A flaw was found in KubeVirt's virt-handler component. This vulnerability allows an authenticated OpenShift user with edit permissions in a single namespace to exploit improper symlink validation when connecting to virtual machine console sockets. By replacing the console socket with a symlink to the host's container runtime (CRI-O) socket, an attacker can hijack virt-handler's privileged connection. This enables the attacker to access any Unix socket on the host, potentially leading to full control of the node and the entire cluster.
CVE-2026-7374
Kubevirt: kubevirt virt-handler: privilege escalation and node compromise via symlink following vulnerability
SUSE-SU-2026:2077-1
Security update for kubevirt
SUSE-SU-2026:2401-1
Security update for kubevirt-1.6
SUSE-SU-2026:2400-1
Security update for kubevirt
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-7jcp-v9w4-wjmg KubeVirt has a Link Following vulnerability | CVSS3: 9.9 | 1% Низкий | 2 месяца назад | |
CVE-2026-7374 A flaw was found in KubeVirt's virt-handler component. This vulnerability allows an authenticated OpenShift user with edit permissions in a single namespace to exploit improper symlink validation when connecting to virtual machine console sockets. By replacing the console socket with a symlink to the host's container runtime (CRI-O) socket, an attacker can hijack virt-handler's privileged connection. This enables the attacker to access any Unix socket on the host, potentially leading to full control of the node and the entire cluster. | CVSS3: 9.9 | 1% Низкий | 2 месяца назад | |
CVE-2026-7374 A flaw was found in KubeVirt's virt-handler component. This vulnerability allows an authenticated OpenShift user with edit permissions in a single namespace to exploit improper symlink validation when connecting to virtual machine console sockets. By replacing the console socket with a symlink to the host's container runtime (CRI-O) socket, an attacker can hijack virt-handler's privileged connection. This enables the attacker to access any Unix socket on the host, potentially leading to full control of the node and the entire cluster. | CVSS3: 9.9 | 1% Низкий | 2 месяца назад | |
CVE-2026-7374 Kubevirt: kubevirt virt-handler: privilege escalation and node compromise via symlink following vulnerability | CVSS3: 9.9 | 1% Низкий | 2 месяца назад | |
SUSE-SU-2026:2077-1 Security update for kubevirt | 1% Низкий | 2 месяца назад | ||
SUSE-SU-2026:2401-1 Security update for kubevirt-1.6 | около 2 месяцев назад | |||
SUSE-SU-2026:2400-1 Security update for kubevirt | около 2 месяцев назад |
Уязвимостей на страницу