Redhat

Openshift Virtualization

21 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.52%
  • Veröffentlicht 28.05.2026 08:15:39
  • Zuletzt bearbeitet 24.08.2026 13:19:22

A flaw was found in KubeVirt's virt-exportserver component. An attacker with specific namespace-level access can exploit a path traversal vulnerability in the VMExport directory endpoint. By placing a symbolic link (symlink) within an exported filesy...

  • EPSS 0.6%
  • Veröffentlicht 26.05.2026 13:14:53
  • Zuletzt bearbeitet 24.08.2026 13:19:19

A flaw was found in KubeVirt's virt-handler component. This vulnerability allows an authenticated OpenShift user with edit permissions in a single namespace to exploit improper symlink validation when connecting to virtual machine console sockets. By...

  • EPSS 0.15%
  • Veröffentlicht 15.04.2026 18:22:30
  • Zuletzt bearbeitet 17.04.2026 15:08:01

A flaw was found in KubeVirt's Role-Based Access Control (RBAC) evaluation logic. The authorization mechanism improperly truncates subresource names, leading to incorrect permission evaluations. This allows authenticated users with specific custom ro...

  • EPSS 0.26%
  • Veröffentlicht 26.01.2026 19:36:43
  • Zuletzt bearbeitet 15.04.2026 00:35:42

A flaw was found in kubevirt. A user within a virtual machine (VM), if the guest agent is active, can exploit this by causing the agent to report an excessive number of network interfaces. This action can overwhelm the system's ability to store VM co...

  • EPSS 0.18%
  • Veröffentlicht 23.10.2025 20:15:40
  • Zuletzt bearbeitet 06.08.2026 11:16:28

A container privilege escalation flaw was found in certain Container-native Virtualization images. This issue stems from the /etc/passwd file being created with group-writable permissions during build time. In certain conditions, an attacker who can ...

  • EPSS 0.64%
  • Veröffentlicht 03.04.2024 14:15:18
  • Zuletzt bearbeitet 15.04.2026 00:35:42

A NULL pointer dereference flaw was found in KubeVirt. This flaw allows an attacker who has access to a virtual machine guest on a node with DownwardMetrics enabled to cause a denial of service by issuing a high number of calls to vm-dump-metrics --v...

  • EPSS 0.4%
  • Veröffentlicht 03.04.2024 14:15:17
  • Zuletzt bearbeitet 15.04.2026 00:35:42

An information disclosure flaw was found in OpenShift Virtualization. The DownwardMetrics feature was introduced to expose host metrics to virtual machine guests and is enabled by default. This issue could expose limited host metrics of a node to any...

Medienbericht Exploit
  • EPSS 93.31%
  • Veröffentlicht 18.12.2023 16:15:10
  • Zuletzt bearbeitet 12.05.2026 11:16:15

The SSH transport protocol with certain OpenSSH extensions, found in OpenSSH before 9.6 and other products, allows remote attackers to bypass integrity checks such that some packets are omitted (from the extension negotiation message), and a client a...

Warnung Medienbericht Exploit
  • EPSS 100%
  • Veröffentlicht 10.10.2023 14:15:10
  • Zuletzt bearbeitet 11.08.2026 19:37:30

The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023.

Exploit
  • EPSS 0.26%
  • Veröffentlicht 07.06.2021 20:15:08
  • Zuletzt bearbeitet 21.11.2024 05:11:17

An insecure modification vulnerability flaw was found in containers using nmstate/kubernetes-nmstate-handler. An attacker with access to the container could use this flaw to modify /etc/passwd and escalate their privileges. Versions before kubernetes...