Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…
EPSS 0.1%top 98%

Red Hat Security Advisory: OpenShift Virtualization v4.22 Images

0
Medium
Published: 08/06/2026 (08/06/2026, 07:22:49 UTC)
Source: GCVE Database
Vendor/Project: Red Hat Product Security
Product: Red Hat

Description

A vulnerability in KubeVirt's safepath package used by virt-handler in OpenShift Virtualization v4.22 allows symlink dereferencing that defeats no-follow protections. An attacker with access to a virt-launcher pod can hijack virt-handler's IPC notify socket, injecting arbitrary VM lifecycle events. This can cause incorrect VM lifecycle actions, corrupt VM state in the Kubernetes API, or crash virt-handler, resulting in denial of VM management services on the affected node. Additionally, the flaw allows unintended file ownership or permission changes on the host, though mitigated by SELinux and immutable filesystem layers in default deployments.

Affected software

Affected versions
Red HatRed Hat Container Native VirtualizationRed Hat Container Native Virtualization 4.22amd64registry.redhat.io/container-native-virtualization/iommufd-device-plugin-rhel9@sha256:8f56dc0fec3ea355dbb8f0b28d74c1d13a125e8050a4d26f32973ca3359f42e1_amd64

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 08/06/2026, 18:43:53 UTC

Technical Analysis

CVE-2026-13201 is a vulnerability in the safepath package of KubeVirt's virt-handler component, part of Red Hat OpenShift Virtualization v4.22. The OpenAtNoFollow function uses O_PATH|O_NOFOLLOW to obtain a file descriptor to a path leaf, but subsequent operations resolve the path via /proc/self/fd/N, which dereferences symlinks, defeating the intended no-follow protection. An attacker with access to a virt-launcher pod can replace the notify socket path with a symlink to an attacker-controlled socket, enabling injection of arbitrary VM domain lifecycle events. Since virt-handler trusts this IPC channel, injected events can cause incorrect VM lifecycle actions (shutdown, restart, migration), corrupt VMI resource state, or crash virt-handler. Because virt-handler runs as a single DaemonSet pod per node, crashing it results in denial of VM management services for all VMs on that node. A secondary impact is that virt-handler can be tricked into applying chown/chmod operations to unintended host files, though this is limited by SELinux enforcing mode and immutable filesystem layers in default OpenShift deployments. No current mitigation fully addresses the notify socket hijacking vector. The vulnerability is tracked as CWE-61 (Unix Symbolic Link Following).

Potential Impact

The vulnerability allows a namespace-level attacker with pod access to hijack virt-handler's IPC notify socket, injecting arbitrary VM lifecycle events that can cause incorrect VM shutdowns, restarts, migrations, or corrupt VM state in the Kubernetes API. It can also crash virt-handler, causing sustained denial of VM management services on the affected node, impacting all virtual machines managed by that node. The secondary impact is unauthorized file ownership or permission changes on the host filesystem by virt-handler, although this is constrained by SELinux enforcing mode and immutable filesystem layers in default OpenShift Virtualization deployments.

Mitigation Recommendations

Red Hat recommends reviewing and restricting RBAC policies to limit pod and exec permissions on virt-launcher pods to only necessary users, reducing the attacker pool able to place symlinks. Ensure SELinux is in enforcing mode to limit the impact of unauthorized file ownership or permission changes. Immutable filesystem layers in RHCOS also help prevent modification of core OS files. Note that no mitigation currently prevents the notify socket hijacking attack vector. Applying all previously released errata before this update is advised. Monitor Red Hat advisories for future fixes addressing this issue.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Csaf Category
csaf_security_advisory
Csaf Version
2.0
Publisher
Red Hat Product Security
Advisory Id
RHSA-2026:51031
Cve Count
1
Additional Cves
[]
Cvss Version
null

Threat ID: 6a74cf8fbf8831d5391aef44

Added to database: 08/06/2026, 18:16:47 UTC

Last enriched: 08/06/2026, 18:43:53 UTC

Last updated: 08/07/2026, 03:40:59 UTC

Views: 4

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses