Skip to main content
EPSS 0.5%top 57%

Kubevirt: kubevirt: vmexport directory symlink escape enables exporter pod file read

0
High
Published: 05/31/2026 (05/31/2026, 01:02:34 UTC)
Source: GCVE Database
Vendor/Project: Microsoft Security Response Center
Product: Microsoft

Description

To determine the support lifecycle for your software, see the Microsoft Support Lifecycle: https://support.microsoft.com/lifecycle

Affected software

Affected versions
>=4.17 <4.19Red HatRed Hat Container Native VirtualizationRed Hat Container Native Virtualization 4.21amd64registry.redhat.io/container-native-virtualization/libguestfs-tools-rhel9@sha256:8d921ac8b01fe1ef96f1df1f4bd75fb5208076288d2918d6cfdc52f1ac6fa254_amd64Red Hat Container Native Virtualization 4.18registry.redhat.io/container-native-virtualization/libguestfs-tools-rhel9@sha256:be8006d401d2af27a90f921e01ff5ef2c53782c17e94f62f56e8e7549db81e59_amd64Red Hat Container Native Virtualization 4.19registry.redhat.io/container-native-virtualization/libguestfs-tools-rhel9@sha256:021c391d7fc4f67c7bd9ecc7684ea23a6a4902170b2b4e666c42fc38bd781d56_amd64Red Hat Container Native Virtualization 4.20registry.redhat.io/container-native-virtualization/libguestfs-tools-rhel9@sha256:a9cfb3720b0f4198e869a61f96c35409e1a29702d67217d5e20ccd456677e1c7_amd64Red Hat Container Native Virtualization 4.17registry.redhat.io/container-native-virtualization/libguestfs-tools-rhel9@sha256:d5362a5b0d676c4b029435c48dda147bc595cfb7c04b197e72f387b1e76093b8_amd64Red Hat Container Native Virtualization 4.2MicrosoftAzure Linux3.0Azure Linux 3.0kubevirt

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 08/10/2026, 19:42:06 UTC

Technical Analysis

CVE-2026-35469 is a denial of service vulnerability in the SPDY streaming code utilized by Kubelet, CRI-O, and kube-apiserver within Red Hat OpenShift Virtualization. Exploitation requires an attacker to have specific elevated cluster roles, such as permissions for pod port forwarding, execution, attachment, or node proxying. Successful exploitation can cause these critical components to become unresponsive, impacting availability. The vulnerability is tracked under CWE-770 (Allocation of Resources Without Limits or Throttling). Red Hat has released OpenShift Virtualization v4.19 images containing fixes for this issue. Mitigation includes restricting assignment of the relevant Kubernetes cluster roles to trusted users only.

Potential Impact

The vulnerability can cause denial of service by making Kubelet, CRI-O, and kube-apiserver components unresponsive, impacting the availability of OpenShift Container Platform environments using affected versions. No confidentiality or integrity impacts are reported. Exploitation requires low privileges but specific elevated cluster roles. There are no known exploits in the wild at this time.

Mitigation Recommendations

Red Hat has released OpenShift Virtualization v4.19 images that fix this vulnerability. Users should update to version 4.19 or later. Additionally, review and restrict Kubernetes cluster roles that allow pod port forwarding (create), pod execution (create), pod attachment (create), and node proxying (get/create) to trusted and authorized users only. Modifying RBAC policies should be tested carefully to avoid disrupting legitimate application functionality. No other fixes or mitigations are indicated by the vendor advisory.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Csaf Category
csaf_security_advisory
Csaf Version
2.0
Publisher
Red Hat Product Security
Advisory Id
RHSA-2026:27914
Cve Count
2
Additional Cves
["CVE-2026-35469"]
Cvss Version
3.1
State
PUBLISHED

Threat ID: 6a395a04eed863c81e08e2f8

Added to database: 06/22/2026, 15:51:32 UTC

Last enriched: 08/10/2026, 19:42:06 UTC

Last updated: 09/21/2026, 10:01:35 UTC

Views: 203

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses