Database/Kernel, userspace & hypervisor

KubeVirt virt-handler (symlink following in migration proxy): During live migration virt-handler dials Unix sockets
Impact
During live migration virt-handler dials Unix sockets inside the target virt-launcher pod through /proc/<pid>/root/ without symlink protection, and those paths sit in qemu-owned directories the launcher user can write. A tenant who controls a VM's launcher redirects the handler into arbitrary host paths, escalating out of the pod with scope change.
Who can reach it
A tenant with control inside a virt-launcher pod, triggering or riding a live migration.
What to do
Apply the Red Hat OpenShift Virtualization errata (RHSA-2026:51031 / RHSA-2026:53655) or upgrade upstream KubeVirt. Operator-driven rolling update of virt-handler across nodes; VMs keep running but migrations should be paused during the rollout.
References
Related entries
- SSSD LDAP sudo provider: unscoped sudoRole search lets any LDAP writer grant themselves root fleet-wideCVE-2026-14474 · SSSD LDAP sudo provider (ldap_sudo_search_base unset)High
- Linux kernel (arch/x86/kvm): An emulated MMIO write that straddles a page boundary onto a second MMIO page is splitCVE-2026-31588 · Linux kernel (arch/x86/kvm)High
- Linux kernel (drivers/iommu/generic_pt): When an unmap lands in the middle of a large or contiguous page-table entryCVE-2026-31735 · Linux kernel (drivers/iommu/generic_pt)High
- OpenSSL: use-after-free in PKCS7_verify when a signed message carries an empty digestAlgorithms setCVE-2026-45447 · OpenSSL PKCS7_verify (empty digestAlgorithms SET)High
- Linux kernel (drivers/iommu/intel): A live 512-bit VT-d PASID entry is replaced with a single structure copy, so theCVE-2026-45945 · Linux kernel (drivers/iommu/intel)High
- Linux kernel (arch/x86/kvm/mmu): The shadow MMU derives GFNs for direct shadow pages arithmetically, which breaks ifCVE-2026-46113 · Linux kernel (arch/x86/kvm/mmu)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.