Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-13622— Kubevirt: virt-handler-rhel9: kubevirt: virt-handler migration proxy follows symlinks allowing container escape to host

Quick assessment

Affected
Red Hat Red Hat Container Native Virtualization 4.12
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

KubeVirt是KubeVirt组织开源的一款用于在 Kubernetes 上直接运行和管理虚拟机的开源工具,让容器化应用和传统虚拟机工作负载可以在同一个平台上共存。 KubeVirt存在路径遍历漏洞,该漏洞源于virt-handler迁移代理使用net.Dial()连接Unix套接字时未进行符号链接保护,可能导致具有命名空间编辑和pods/exec权限的攻击者将迁移代理套接字替换为指向宿主CRI-O套接字的符号链接,从而完全控制节点。

CVSS 8.8 · High EPSS 0.20% · P9
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-13622

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Kubevirt: virt-handler-rhel9: kubevirt: virt-handler migration proxy follows symlinks allowing container escape to host
Source: CVE Program / CVE List V5
Vulnerability Description
A symlink following vulnerability was found in KubeVirt's virt-handler migration proxy. During live migration, virt-handler dials Unix sockets inside the target virt-launcher pod via /proc/<pid>/root/ paths using net.Dial() without symlink protection. These socket paths reside in qemu-owned directories writable by the virt-launcher user. An attacker with namespace edit and pods/exec permissions can replace a migration proxy socket with a symlink to the host CRI-O socket. Because virt-handler runs as root in the host mount namespace, absolute symlink targets resolve against the host filesystem, and the bidirectional io.Copy proxy relays attacker-controlled bytes to the container runtime, enabling full node compromise.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
对路径名的限制不恰当(路径遍历)
Source: CVE Program / CVE List V5
Vulnerability Title
KubeVirt 路径遍历漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
KubeVirt是KubeVirt组织开源的一款用于在 Kubernetes 上直接运行和管理虚拟机的开源工具,让容器化应用和传统虚拟机工作负载可以在同一个平台上共存。 KubeVirt存在路径遍历漏洞,该漏洞源于virt-handler迁移代理使用net.Dial()连接Unix套接字时未进行符号链接保护,可能导致具有命名空间编辑和pods/exec权限的攻击者将迁移代理套接字替换为指向宿主CRI-O套接字的符号链接,从而完全控制节点。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

Vendor Product Affected Versions CPE Subscribe
Red Hat Red Hat Container Native Virtualization 4.12 1785837722 ~ * cpe:/a:redhat:container_native_virtualization:4.12::el8
Red Hat Red Hat Container Native Virtualization 4.13 1786346596 ~ * cpe:/a:redhat:container_native_virtualization:4.13::el9
Red Hat Red Hat Container Native Virtualization 4.14 1786309624 ~ * cpe:/a:redhat:container_native_virtualization:4.14::el9
Red Hat Red Hat Container Native Virtualization 4.15 1786347656 ~ * cpe:/a:redhat:container_native_virtualization:4.15::el9
Red Hat Red Hat Container Native Virtualization 4.16 1786030071 ~ * cpe:/a:redhat:container_native_virtualization:4.16::el9
Red Hat Red Hat Container Native Virtualization 4.17 1786348529 ~ * cpe:/a:redhat:container_native_virtualization:4.17::el9
Red Hat Red Hat Container Native Virtualization 4.18 1786130068 ~ * cpe:/a:redhat:container_native_virtualization:4.18::el9
Red Hat Red Hat Container Native Virtualization 4.19 1786334215 ~ * cpe:/a:redhat:container_native_virtualization:4.19::el9
Red Hat Red Hat Container Native Virtualization 4.20 1785831334 ~ * cpe:/a:redhat:container_native_virtualization:4.20::el9
Red Hat Red Hat Container Native Virtualization 4.21 1785829701 ~ * cpe:/a:redhat:container_native_virtualization:4.21::el9
Red Hat Red Hat Container Native Virtualization 4.22 1785140336 ~ * cpe:/a:redhat:container_native_virtualization:4.22::el9

II. Public POCs for CVE-2026-13622

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-13622

请登录查看更多情报信息。

Vendor Advisories for CVE-2026-13622 (13)

Same Patch Batch · Red Hat · 2026-08-12 · 19 CVEs total

CVE-2026-72526 9.9 CRITICAL Multicloud-integrations: multicloud-integrations: pull-model propagation allows hub tenant
CVE-2026-72508 9.9 CRITICAL Multicloud-operators-subscription: multicloud-operators-subscription: hub and spoke servic
CVE-2026-73268 9.9 CRITICAL Cluster-curator-controller: cluster-curator-controller: spec.install.overridejob allows ar
CVE-2026-73269 9.9 CRITICAL Cluster-curator-controller: cluster-curator-controller: tenant-controllable trigger create
CVE-2026-70398 9.6 CRITICAL Multicloud-integrations: multicloud-integrations: gitopscluster.spec.argoserver.argonamesp
CVE-2026-71471 9.0 CRITICAL Acm-search-v2-rhel9: search-v2-operator: hub search cr collector.imageoverride propagated
CVE-2026-71473 8.5 HIGH Acm-search-v2-rhel9: search-v2-operator: addonfactory.getvaluesfromaddonannotation enables
CVE-2026-73122 7.7 HIGH Multicloud-operators-channel: multicloud-operators-channel: auto-generated role grants eve
CVE-2026-66878 7.7 HIGH Multicloud-operators-subscription: multicloud-operators-subscription: fetchchannelreferenc
CVE-2026-19654 7.5 HIGH Rsyslog: a configuration-dependent issue in rsyslog's optional imptcp input module can all
CVE-2026-71469 7.5 HIGH Acm-search-v2-api-rhel9: search-v2-api: unbounded tokenreviews cache allows unauthenticate
CVE-2026-18726 6.5 MEDIUM Open-iscsi: open-iscsi: denial of service in iscsiuio router advertisement parsing
CVE-2026-18727 6.5 MEDIUM Open-iscsi: open-iscsi: integer underflow in iscsiuio dhcpv6 parsing
CVE-2026-71846 6.5 MEDIUM Insights-client: insights-client: clusterrole grants cluster-wide secrets get/list/watch b
CVE-2026-64927 6.4 MEDIUM Multicloud-operators-channel: multicloud-operators-channel: cross-namespace secret and con
CVE-2026-18663 5.9 MEDIUM 389-ds-base: 389-ds-base: pre-authentication double-free in get_ldapmessage_controls_ext()
CVE-2026-19130 5.8 MEDIUM Provider-credential-controller: provider-credential-controller: cross-namespace credential
CVE-2026-19548 5.5 MEDIUM Binutils: binutils: multiple use-after-free in add_archive_element via lto plugin processi

IV. Related Vulnerabilities

V. Comments for CVE-2026-13622

No comments yet


Leave a comment