Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…
EPSS 0.1%top 98%

CVE-2026-13201: UNIX Symbolic Link (Symlink) Following in Red Hat Red Hat Container Native Virtualization 4.22

0
High
Published: 06/24/2026 (06/24/2026, 20:39:00 UTC)
Source: GCVE Database
Vendor/Project: Red Hat
Product: Red Hat Container Native Virtualization 4.22

Description

A vulnerability in KubeVirt's safepath package allows an attacker with access to a virt-launcher pod to hijack virt-handler's notify socket by exploiting symlink dereferencing. This can lead to injection of arbitrary VM lifecycle events, causing incorrect VM actions, VM state corruption in the Kubernetes API, or crashing virt-handler, resulting in denial of VM management services on the node. Additionally, the flaw allows unintended file ownership or permission changes on the host, though mitigated by SELinux and immutable filesystem layers in default OpenShift deployments.

CVSS v3.1

Score 7.3high

Attack Vector
Local
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Changed
Confidentiality
None
Integrity
Low
Availability
High
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:L/A:H

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 08/06/2026, 18:28:40 UTC

Technical Analysis

The vulnerability (CVE-2026-13201) exists in KubeVirt's safepath package used by virt-handler. The OpenAtNoFollow function uses O_PATH|O_NOFOLLOW flags to obtain a file descriptor to a path leaf, intending to avoid following symlinks. However, downstream operations resolve the path via /proc/self/fd/N, which dereferences symlinks, defeating the no-follow protection. An attacker with access to a virt-launcher pod can replace the notify socket path with a symlink to an attacker-controlled socket, enabling injection of arbitrary VM domain lifecycle events into virt-handler. Since virt-handler trusts this IPC channel, injected events can cause incorrect VM lifecycle actions, corrupt VM state in the Kubernetes API, or crash virt-handler, resulting in denial of VM management services on the node. A secondary impact allows virt-handler, running as root, to apply file ownership or permission changes to unintended host files, though this is limited by SELinux enforcing mode and immutable filesystem layers in default OpenShift Virtualization deployments.

Potential Impact

The primary impact is hijacking of the notify socket used by virt-handler, enabling injection of arbitrary VM lifecycle events without validation. This can cause incorrect VM lifecycle actions such as shutdowns, restarts, or migrations, corrupt VM instance resource state in the Kubernetes API, or crash the virt-handler process. Because virt-handler runs as a single DaemonSet pod per node, a crash loop causes sustained denial of VM management services for all VMs on that node, including console access and live migration. The secondary impact is unauthorized file ownership or permission changes on host files by virt-handler running as root, but this is constrained by SELinux enforcing mode and immutable filesystem layers in default OpenShift deployments. The attacker cannot read or write file contents and remains confined to the container.

Mitigation Recommendations

No fix is currently available for the notify socket hijacking vector. Mitigation focuses on reducing the attacker pool and limiting secondary impact by reviewing and restricting RBAC policies to limit pod and exec permissions on virt-launcher pods to only necessary users. Ensure SELinux is in enforcing mode to restrict file targets for chown/chmod operations. Immutable filesystem layers in RHCOS prevent modification of core OS files. Note that SELinux and filesystem immutability do not prevent notify socket hijacking. Monitor Red Hat advisories for updates and apply patches when released.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Osv Id
GHSA-rcfc-7m3g-h5xh
Osv Schema Version
1.4.0
Aliases
["CVE-2026-13201"]
Ecosystems
[]
Database Specific Severity
MODERATE
Cvss Version
3.1

Threat ID: 6a74cf85bf8831d5391ad292

Added to database: 08/06/2026, 18:16:37 UTC

Last enriched: 08/06/2026, 18:28:40 UTC

Last updated: 08/07/2026, 03:40:59 UTC

Views: 3

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses