A symlink following vulnerability was found in KubeVirt's virt-handler migration proxy. During live migration, virt-handler dials Unix sockets inside the target virt-launcher pod via /proc/<pid>/root/ paths using net.Dial() without symlink protection. These socket paths reside in qemu-owned directories writable by the virt-launcher user. An attacker with namespace edit and pods/exec permissions can replace a migration proxy socket with a symlink to the host CRI-O socket. Because virt-handler runs as root in the host mount namespace, absolute symlink targets resolve against the host filesystem, and the bidirectional io.Copy proxy relays attacker-controlled bytes to the container runtime, enabling full node compromise.

Project Subscriptions

Vendors Products
Kubevirt Subscribe
Kubevirt Subscribe
Container Native Virtualization Subscribe
Openshift Virtualization Subscribe
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

Restrict pods/exec permissions in namespaces that run virtual machines. The pods/exec RBAC permission is required for the attack — removing it from VM operator roles prevents exploitation. Additionally, enable Kubernetes audit logging and monitor for kubectl exec commands targeting virt-launcher pods, especially during live migration events.

History

Fri, 14 Aug 2026 10:30:00 +0000

Type Values Removed Values Added
CPEs cpe:/a:redhat:container_native_virtualization:4 cpe:/a:redhat:container_native_virtualization:4.12::el8
cpe:/a:redhat:container_native_virtualization:4.15::el9
cpe:/a:redhat:container_native_virtualization:4.16::el9
cpe:/a:redhat:container_native_virtualization:4.19::el9
cpe:/a:redhat:container_native_virtualization:4.21::el9
References

Fri, 14 Aug 2026 08:15:00 +0000

Type Values Removed Values Added
CPEs cpe:/a:redhat:container_native_virtualization:4.13::el9
cpe:/a:redhat:container_native_virtualization:4.14::el9
cpe:/a:redhat:container_native_virtualization:4.17::el9
cpe:/a:redhat:container_native_virtualization:4.18::el9
cpe:/a:redhat:container_native_virtualization:4.20::el9
cpe:/a:redhat:container_native_virtualization:4.22::el9
References

Thu, 13 Aug 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 13 Aug 2026 12:15:00 +0000

Type Values Removed Values Added
References
Metrics threat_severity

None

threat_severity

Important


Thu, 13 Aug 2026 11:00:00 +0000

Type Values Removed Values Added
First Time appeared Kubevirt
Kubevirt kubevirt
Redhat openshift Virtualization
Vendors & Products Kubevirt
Kubevirt kubevirt
Redhat openshift Virtualization

Wed, 12 Aug 2026 21:00:00 +0000

Type Values Removed Values Added
Description A symlink following vulnerability was found in KubeVirt's virt-handler migration proxy. During live migration, virt-handler dials Unix sockets inside the target virt-launcher pod via /proc/<pid>/root/ paths using net.Dial() without symlink protection. These socket paths reside in qemu-owned directories writable by the virt-launcher user. An attacker with namespace edit and pods/exec permissions can replace a migration proxy socket with a symlink to the host CRI-O socket. Because virt-handler runs as root in the host mount namespace, absolute symlink targets resolve against the host filesystem, and the bidirectional io.Copy proxy relays attacker-controlled bytes to the container runtime, enabling full node compromise.
Title Kubevirt: virt-handler-rhel9: kubevirt: virt-handler migration proxy follows symlinks allowing container escape to host
First Time appeared Redhat
Redhat container Native Virtualization
Weaknesses CWE-22
CPEs cpe:/a:redhat:container_native_virtualization:4
Vendors & Products Redhat
Redhat container Native Virtualization
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published:

Updated: 2026-08-14T10:01:06.976Z

Reserved: 2026-06-29T09:41:40.974Z

Link: CVE-2026-13622

cve-icon Vulnrichment

Updated: 2026-08-13T19:21:38.756Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-08-12T21:17:35.630

Modified: 2026-08-14T19:07:46.080

Link: CVE-2026-13622

cve-icon Redhat

Severity : Important

Publid Date: 2026-08-12T00:00:00Z

Links: CVE-2026-13622 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-08-13T10:39:13Z

Weaknesses