kubevirt1.9-container-disk-1.9.0-3.1 on GA media
These are all security issues fixed in the kubevirt1.9-container-disk-1.9.0-3.1 package on the GA media of openSUSE Tumbleweed.
AI Analysis
Technical Summary
CVE-2026-13622 is a path traversal vulnerability (CWE-22) in Red Hat Container Native Virtualization 4.12 images used in OpenShift Virtualization. This flaw allows improper limitation of pathname access, which could be exploited to access or modify files outside the intended restricted directories. The vulnerability affects versions >=4.12 and <4.13. The CVSS 3.1 score is 8.8 (AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H), indicating a local attack vector with low complexity and privileges required, no user interaction, and a scope change with high impact on confidentiality, integrity, and availability. Vendor advisories confirm the vulnerability but do not list any fixes or patches as of the latest updates. No known exploits have been reported in the wild.
Potential Impact
The vulnerability allows an attacker with local privileges to perform path traversal attacks, potentially leading to unauthorized disclosure, modification, or destruction of data within the affected Red Hat Container Native Virtualization environment. The high CVSS score reflects the critical impact on confidentiality, integrity, and availability if exploited. However, exploitation requires local access and low privileges, and no active exploitation has been reported.
Mitigation Recommendations
As of the latest vendor advisories, no fixes or patches are available for this vulnerability. Users should ensure all previously released errata are applied and monitor Red Hat's official advisories for updates. Since this is a local vulnerability, restricting local access and applying general security best practices to limit privilege escalation may reduce risk until a patch is released.
kubevirt1.9-container-disk-1.9.0-3.1 on GA media
Description
These are all security issues fixed in the kubevirt1.9-container-disk-1.9.0-3.1 package on the GA media of openSUSE Tumbleweed.
Affected software
pkg:rpm/redhat/redhat-container-native-virtualizationRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-13622 is a path traversal vulnerability (CWE-22) in Red Hat Container Native Virtualization 4.12 images used in OpenShift Virtualization. This flaw allows improper limitation of pathname access, which could be exploited to access or modify files outside the intended restricted directories. The vulnerability affects versions >=4.12 and <4.13. The CVSS 3.1 score is 8.8 (AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H), indicating a local attack vector with low complexity and privileges required, no user interaction, and a scope change with high impact on confidentiality, integrity, and availability. Vendor advisories confirm the vulnerability but do not list any fixes or patches as of the latest updates. No known exploits have been reported in the wild.
Potential Impact
The vulnerability allows an attacker with local privileges to perform path traversal attacks, potentially leading to unauthorized disclosure, modification, or destruction of data within the affected Red Hat Container Native Virtualization environment. The high CVSS score reflects the critical impact on confidentiality, integrity, and availability if exploited. However, exploitation requires local access and low privileges, and no active exploitation has been reported.
Mitigation Recommendations
As of the latest vendor advisories, no fixes or patches are available for this vulnerability. Users should ensure all previously released errata are applied and monitor Red Hat's official advisories for updates. Since this is a local vulnerability, restricting local access and applying general security best practices to limit privilege escalation may reduce risk until a patch is released.
Technical Details
- Gcve Source
- db.gcve.eu
- Csaf Category
- csaf_security_advisory
- Csaf Version
- 2.0
- Publisher
- Red Hat Product Security
- Advisory Id
- RHEA-2026:53670
- Cve Count
- 1
- State
- PUBLISHED
Threat ID: 6a7f4405bf8831d5395fb31e
Added to database: 08/14/2026, 16:36:21 UTC
Last enriched: 09/12/2026, 03:16:55 UTC
Last updated: 09/27/2026, 01:47:40 UTC
Views: 49
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.