CVE-2026-102623: NULL Pointer Dereference in Red Hat Red Hat OpenShift Virtualization 4
CVE-2026-102623 is a denial of service vulnerability in Red Hat OpenShift Virtualization 4's KubeVirt component. An authenticated user with permission to create Virtual Machine Instances can submit a virtual machine definition with an empty ephemeral volume, causing the virt-controller to crash repeatedly. This disrupts virtual machine lifecycle operations cluster-wide but does not allow code execution or unauthorized data access. The vulnerability is rated medium severity with a CVSS score of 6.5. No official fix or mitigation currently meets Red Hat's criteria for deployment.
AI Analysis
Technical Summary
This vulnerability in KubeVirt arises from improper validation of ephemeral volume configurations in virtual machine definitions. When an authenticated user with namespace privileges creates a Virtual Machine Instance with an empty ephemeral volume, the virt-controller component encounters a NULL pointer dereference, triggering an unhandled exception and crashing. The malformed definition remains in the cluster, causing the controller to enter a continuous crash loop and disrupting virtual machine lifecycle management across the environment. The flaw does not enable arbitrary code execution, privilege escalation, or unauthorized access to sensitive data. Red Hat rates this issue as moderate severity due to the requirement for authenticated user privileges and the limited scope of impact.
Potential Impact
Exploitation results in a denial of service condition by causing the virt-controller to crash repeatedly, disrupting virtual machine lifecycle operations cluster-wide. There is no impact on confidentiality or integrity, and no unauthorized code execution or privilege escalation is possible. The threat is limited to authenticated users with permission to create VMIs within a namespace.
Mitigation Recommendations
Currently, no mitigation or patch meets Red Hat's criteria for ease of use, applicability, or stability. Users should monitor Red Hat advisories for updates. Since exploitation requires authenticated user privileges, restricting such permissions can reduce risk. No official fix is available at this time.
CVE-2026-102623: NULL Pointer Dereference in Red Hat Red Hat OpenShift Virtualization 4
Description
CVE-2026-102623 is a denial of service vulnerability in Red Hat OpenShift Virtualization 4's KubeVirt component. An authenticated user with permission to create Virtual Machine Instances can submit a virtual machine definition with an empty ephemeral volume, causing the virt-controller to crash repeatedly. This disrupts virtual machine lifecycle operations cluster-wide but does not allow code execution or unauthorized data access. The vulnerability is rated medium severity with a CVSS score of 6.5. No official fix or mitigation currently meets Red Hat's criteria for deployment.
CVSS v3.1
Score 6.5medium
Affected software
Red Hat
Red Hat OpenShift Virtualization 4
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
This vulnerability in KubeVirt arises from improper validation of ephemeral volume configurations in virtual machine definitions. When an authenticated user with namespace privileges creates a Virtual Machine Instance with an empty ephemeral volume, the virt-controller component encounters a NULL pointer dereference, triggering an unhandled exception and crashing. The malformed definition remains in the cluster, causing the controller to enter a continuous crash loop and disrupting virtual machine lifecycle management across the environment. The flaw does not enable arbitrary code execution, privilege escalation, or unauthorized access to sensitive data. Red Hat rates this issue as moderate severity due to the requirement for authenticated user privileges and the limited scope of impact.
Potential Impact
Exploitation results in a denial of service condition by causing the virt-controller to crash repeatedly, disrupting virtual machine lifecycle operations cluster-wide. There is no impact on confidentiality or integrity, and no unauthorized code execution or privilege escalation is possible. The threat is limited to authenticated users with permission to create VMIs within a namespace.
Mitigation Recommendations
Currently, no mitigation or patch meets Red Hat's criteria for ease of use, applicability, or stability. Users should monitor Red Hat advisories for updates. Since exploitation requires authenticated user privileges, restricting such permissions can reduce risk. No official fix is available at this time.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- redhat
- Date Reserved
- 2026-09-29T14:35:37.210Z
- Cvss Version
- 3.1
- State
- PUBLISHED
- Vendor Advisory Urls
- [{"url":"https://access.redhat.com/security/cve/CVE-2026-102623","vendor":"Red Hat"}]
Threat ID: 6abbf1e294a11e1e08dfc50b
Added to database: 09/29/2026, 17:14:10 UTC
Last enriched: 09/29/2026, 17:33:02 UTC
Last updated: 09/29/2026, 17:40:12 UTC
Views: 5
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.