GPU VulnDB

Database/Kernel, userspace & hypervisor

KubeVirt virt-handler (symlink following in migration proxy): During live migration virt-handler dials Unix sockets

CVE-2026-13622Kernel, userspace & hypervisorcurated

Impact

During live migration virt-handler dials Unix sockets inside the target virt-launcher pod through /proc/<pid>/root/ without symlink protection, and those paths sit in qemu-owned directories the launcher user can write. A tenant who controls a VM's launcher redirects the handler into arbitrary host paths, escalating out of the pod with scope change.

Who can reach it

A tenant with control inside a virt-launcher pod, triggering or riding a live migration.

What to do

Apply the Red Hat OpenShift Virtualization errata (RHSA-2026:51031 / RHSA-2026:53655) or upgrade upstream KubeVirt. Operator-driven rolling update of virt-handler across nodes; VMs keep running but migrations should be paused during the rollout.

References

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.