Redhat

Openshift Virtualization

21 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.14%
  • Veröffentlicht 12.08.2026 20:46:15
  • Zuletzt bearbeitet 22.08.2026 19:16:20

A symlink following vulnerability was found in KubeVirt's virt-handler migration proxy. During live migration, virt-handler dials Unix sockets inside the target virt-launcher pod via /proc/<pid>/root/ paths using net.Dial() without symlink protection...

  • EPSS 0.38%
  • Veröffentlicht 27.07.2026 10:16:37
  • Zuletzt bearbeitet 27.07.2026 20:37:16

In containerized-data-importer (CDI), the aggregated cdi.kubevirt.io:view ClusterRole, intended to provide read-only access to CDI resources, includes a rule granting create on the datavolumes/source subresource. CDI's DataVolume clone authorization ...

  • EPSS 0.16%
  • Veröffentlicht 26.06.2026 16:00:43
  • Zuletzt bearbeitet 06.07.2026 17:51:23

A flaw was found in KubeVirt's network annotation generator. When a tenant creates a VirtualMachineInstance with a Multus network configuration, the supplied networkName value is written verbatim into the launcher pod's v1.multus-cni.io/default-netwo...

  • EPSS 0.18%
  • Veröffentlicht 26.06.2026 10:41:01
  • Zuletzt bearbeitet 04.08.2026 12:16:24

Rejected reason: Red Hat Product Security has come to the conclusion that this CVE is not needed.

  • EPSS 0.09%
  • Veröffentlicht 26.06.2026 00:04:07
  • Zuletzt bearbeitet 06.07.2026 17:25:39

A flaw was found in KubeVirt's downward metrics virtio-serial server. The server reads guest requests using textproto.Reader.ReadLine(), which buffers input indefinitely until a newline character is received, with no length limit or read deadline. A ...

  • EPSS 0.15%
  • Veröffentlicht 25.06.2026 23:23:38
  • Zuletzt bearbeitet 06.07.2026 17:45:33

A server-side request forgery (SSRF) flaw was found in KubeVirt's virt-api port-forward handler. When processing a port-forward request to a VirtualMachineInstance (VMI), virt-api reads the target IP from vmi.Status.Interfaces[0].IP and passes it dir...

  • EPSS 0.11%
  • Veröffentlicht 25.06.2026 23:23:23
  • Zuletzt bearbeitet 06.07.2026 17:46:14

A flaw was found in KubeVirt's virt-handler network cache handling. The WriteToCachedFile function writes data to a launcher-rooted path using os.WriteFile and os.Chown without symlink protection. A user with access to the virt-launcher container can...

  • EPSS 0.09%
  • Veröffentlicht 24.06.2026 21:16:52
  • Zuletzt bearbeitet 06.07.2026 17:51:17

A flaw was found in KubeVirt's virt-handler domain notify server. The gRPC handlers for HandleDomainEvent and HandleK8SEvent derive the VMI identity (namespace/name) solely from the request body without validating it against the connection's origin. ...

  • EPSS 0.15%
  • Veröffentlicht 24.06.2026 21:16:52
  • Zuletzt bearbeitet 22.08.2026 19:16:19

A flaw was found in KubeVirt's safepath package used by virt-handler. The OpenAtNoFollow function uses O_PATH|O_NOFOLLOW to obtain a file descriptor to a path leaf, but downstream operations resolve the path via /proc/self/fd/N using link-following s...

Exploit
  • EPSS 0.78%
  • Veröffentlicht 11.06.2026 15:33:12
  • Zuletzt bearbeitet 24.08.2026 13:18:52

Axios is a promise based HTTP client for the browser and Node.js. From 0.19.0 to before 0.31.1 and 1.15.2, Axios contains prototype-pollution gadgets in request config processing. If another vulnerability in the same JavaScript process has already po...