Database/Kernel, userspace & hypervisor

KubeVirt virt-handler (symlink following in migration proxy): During live migration virt-handler dials Unix sockets
Impact
During live migration virt-handler dials Unix sockets inside the target virt-launcher pod through /proc/<pid>/root/ without symlink protection, and those paths sit in qemu-owned directories the launcher user can write. A tenant who controls a VM's launcher redirects the handler into arbitrary host paths, escalating out of the pod with scope change.
Who can reach it
A tenant with control inside a virt-launcher pod, triggering or riding a live migration.
What to do
Apply the Red Hat OpenShift Virtualization errata (RHSA-2026:51031 / RHSA-2026:53655) or upgrade upstream KubeVirt. Operator-driven rolling update of virt-handler across nodes; VMs keep running but migrations should be paused during the rollout.
References
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.