Red Hat Security Advisory: OpenShift Virtualization v4.22 Images
A vulnerability in KubeVirt's safepath package used by virt-handler in OpenShift Virtualization v4.22 allows symlink dereferencing that defeats no-follow protections. An attacker with access to a virt-launcher pod can hijack virt-handler's IPC notify socket, injecting arbitrary VM lifecycle events. This can cause incorrect VM lifecycle actions, corrupt VM state in the Kubernetes API, or crash virt-handler, resulting in denial of VM management services on the affected node. Additionally, the flaw allows unintended file ownership or permission changes on the host, though mitigated by SELinux and immutable filesystem layers in default deployments.
AI Analysis
Technical Summary
CVE-2026-13201 is a vulnerability in the safepath package of KubeVirt's virt-handler component, part of Red Hat OpenShift Virtualization v4.22. The OpenAtNoFollow function uses O_PATH|O_NOFOLLOW to obtain a file descriptor to a path leaf, but subsequent operations resolve the path via /proc/self/fd/N, which dereferences symlinks, defeating the intended no-follow protection. An attacker with access to a virt-launcher pod can replace the notify socket path with a symlink to an attacker-controlled socket, enabling injection of arbitrary VM domain lifecycle events. Since virt-handler trusts this IPC channel, injected events can cause incorrect VM lifecycle actions (shutdown, restart, migration), corrupt VMI resource state, or crash virt-handler. Because virt-handler runs as a single DaemonSet pod per node, crashing it results in denial of VM management services for all VMs on that node. A secondary impact is that virt-handler can be tricked into applying chown/chmod operations to unintended host files, though this is limited by SELinux enforcing mode and immutable filesystem layers in default OpenShift deployments. No current mitigation fully addresses the notify socket hijacking vector. The vulnerability is tracked as CWE-61 (Unix Symbolic Link Following).
Potential Impact
The vulnerability allows a namespace-level attacker with pod access to hijack virt-handler's IPC notify socket, injecting arbitrary VM lifecycle events that can cause incorrect VM shutdowns, restarts, migrations, or corrupt VM state in the Kubernetes API. It can also crash virt-handler, causing sustained denial of VM management services on the affected node, impacting all virtual machines managed by that node. The secondary impact is unauthorized file ownership or permission changes on the host filesystem by virt-handler, although this is constrained by SELinux enforcing mode and immutable filesystem layers in default OpenShift Virtualization deployments.
Mitigation Recommendations
Red Hat recommends reviewing and restricting RBAC policies to limit pod and exec permissions on virt-launcher pods to only necessary users, reducing the attacker pool able to place symlinks. Ensure SELinux is in enforcing mode to limit the impact of unauthorized file ownership or permission changes. Immutable filesystem layers in RHCOS also help prevent modification of core OS files. Note that no mitigation currently prevents the notify socket hijacking attack vector. Applying all previously released errata before this update is advised. Monitor Red Hat advisories for future fixes addressing this issue.
Red Hat Security Advisory: OpenShift Virtualization v4.22 Images
Description
A vulnerability in KubeVirt's safepath package used by virt-handler in OpenShift Virtualization v4.22 allows symlink dereferencing that defeats no-follow protections. An attacker with access to a virt-launcher pod can hijack virt-handler's IPC notify socket, injecting arbitrary VM lifecycle events. This can cause incorrect VM lifecycle actions, corrupt VM state in the Kubernetes API, or crash virt-handler, resulting in denial of VM management services on the affected node. Additionally, the flaw allows unintended file ownership or permission changes on the host, though mitigated by SELinux and immutable filesystem layers in default deployments.
Affected software
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-13201 is a vulnerability in the safepath package of KubeVirt's virt-handler component, part of Red Hat OpenShift Virtualization v4.22. The OpenAtNoFollow function uses O_PATH|O_NOFOLLOW to obtain a file descriptor to a path leaf, but subsequent operations resolve the path via /proc/self/fd/N, which dereferences symlinks, defeating the intended no-follow protection. An attacker with access to a virt-launcher pod can replace the notify socket path with a symlink to an attacker-controlled socket, enabling injection of arbitrary VM domain lifecycle events. Since virt-handler trusts this IPC channel, injected events can cause incorrect VM lifecycle actions (shutdown, restart, migration), corrupt VMI resource state, or crash virt-handler. Because virt-handler runs as a single DaemonSet pod per node, crashing it results in denial of VM management services for all VMs on that node. A secondary impact is that virt-handler can be tricked into applying chown/chmod operations to unintended host files, though this is limited by SELinux enforcing mode and immutable filesystem layers in default OpenShift deployments. No current mitigation fully addresses the notify socket hijacking vector. The vulnerability is tracked as CWE-61 (Unix Symbolic Link Following).
Potential Impact
The vulnerability allows a namespace-level attacker with pod access to hijack virt-handler's IPC notify socket, injecting arbitrary VM lifecycle events that can cause incorrect VM shutdowns, restarts, migrations, or corrupt VM state in the Kubernetes API. It can also crash virt-handler, causing sustained denial of VM management services on the affected node, impacting all virtual machines managed by that node. The secondary impact is unauthorized file ownership or permission changes on the host filesystem by virt-handler, although this is constrained by SELinux enforcing mode and immutable filesystem layers in default OpenShift Virtualization deployments.
Mitigation Recommendations
Red Hat recommends reviewing and restricting RBAC policies to limit pod and exec permissions on virt-launcher pods to only necessary users, reducing the attacker pool able to place symlinks. Ensure SELinux is in enforcing mode to limit the impact of unauthorized file ownership or permission changes. Immutable filesystem layers in RHCOS also help prevent modification of core OS files. Note that no mitigation currently prevents the notify socket hijacking attack vector. Applying all previously released errata before this update is advised. Monitor Red Hat advisories for future fixes addressing this issue.
Technical Details
- Gcve Source
- db.gcve.eu
- Csaf Category
- csaf_security_advisory
- Csaf Version
- 2.0
- Publisher
- Red Hat Product Security
- Advisory Id
- RHSA-2026:51031
- Cve Count
- 1
- Additional Cves
- []
- Cvss Version
- null
Threat ID: 6a74cf8fbf8831d5391aef44
Added to database: 08/06/2026, 18:16:47 UTC
Last enriched: 08/06/2026, 18:43:53 UTC
Last updated: 08/07/2026, 03:40:59 UTC
Views: 4
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.