KubeVirt virt-handler Symlink Followfor-Privilege Escalation
CVE-2026-13622 Published on August 12, 2026

Kubevirt: virt-handler-rhel9: kubevirt: virt-handler migration proxy follows symlinks allowing container escape to host
A symlink following vulnerability was found in KubeVirt's virt-handler migration proxy. During live migration, virt-handler dials Unix sockets inside the target virt-launcher pod via /proc/<pid>/root/ paths using net.Dial() without symlink protection. These socket paths reside in qemu-owned directories writable by the virt-launcher user. An attacker with namespace edit and pods/exec permissions can replace a migration proxy socket with a symlink to the host CRI-O socket. Because virt-handler runs as root in the host mount namespace, absolute symlink targets resolve against the host filesystem, and the bidirectional io.Copy proxy relays attacker-controlled bytes to the container runtime, enabling full node compromise.

Vendor Advisory Vendor Advisory Vendor Advisory Vendor Advisory Vendor Advisory Vendor Advisory Vendor Advisory Vendor Advisory Vendor Advisory Vendor Advisory Vendor Advisory NVD

Vulnerability Analysis

CVE-2026-13622 is exploitable with local system access, and requires small amount of user privileges. This vulnerability is considered to have a low attack complexity. The potential impact of an exploit of this vulnerability is considered to be very high.

Attack Vector:
LOCAL
Attack Complexity:
LOW
Privileges Required:
LOW
User Interaction:
NONE
Scope:
CHANGED
Confidentiality Impact:
HIGH
Integrity Impact:
HIGH
Availability Impact:
HIGH

Timeline

Reported to Red Hat.

Made public. 44 days later.

Weakness Type

What is a Directory traversal Vulnerability?

The software uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the software does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.

CVE-2026-13622 has been classified to as a Directory traversal vulnerability or weakness.


Products Associated with CVE-2026-13622

Want to know whenever a new CVE is published for Red Hat Container Native Virtualization? stack.watch will email you.

 

Affected Versions

Red Hat Container Native Virtualization 4.12: Red Hat Container Native Virtualization 4.13: Red Hat Container Native Virtualization 4.14: Red Hat Container Native Virtualization 4.15: Red Hat Container Native Virtualization 4.16: Red Hat Container Native Virtualization 4.17: Red Hat Container Native Virtualization 4.18: Red Hat Container Native Virtualization 4.19: Red Hat Container Native Virtualization 4.2: Red Hat Container Native Virtualization 4.21: Red Hat Container Native Virtualization 4.22: