Куда я попал?
SECURITM это SGRC система, ? автоматизирующая процессы в службах информационной безопасности. SECURITM помогает построить и управлять ИСПДн, КИИ, ГИС, СМИБ/СУИБ, банковскими системами защиты.
А еще SECURITM это место для обмена опытом и наработками для служб безопасности.

CVE-2026-13201

PUBLISHED 23.08.2026

CNA: redhat

Kubevirt: virt-handler-rhel9: kubevirt: safepath symlink following in virt-handler enables notify socket hijacking and node-level vm disruption

Обновлено: 23.08.2026
A flaw was found in KubeVirt's safepath package used by virt-handler. The OpenAtNoFollow function uses O_PATH|O_NOFOLLOW to obtain a file descriptor to a path leaf, but downstream operations resolve the path via /proc/self/fd/N using link-following syscalls. When the leaf is a symlink, the kernel dereferences it, defeating the intended no-follow protection. An attacker with access to a virt-launcher pod can exploit this to redirect virt-handler's IPC socket connections, including the notify socket used for VM domain lifecycle events. By hijacking this socket, the attacker can inject arbitrary domain events into virt-handler, causing it to take incorrect lifecycle actions, corrupt VM state in the Kubernetes API, or crash — resulting in sustained denial of VM management services for all virtual machines on the affected node. Additionally, the same symlink following flaw allows virt-handler to apply file ownership or permission changes to unintended host paths.

CWE

Идентификатор Описание
CWE-61 The product, when opening a file or directory, does not sufficiently account for when the file is a symbolic link that resolves to a target outside of the intended control sphere. This could allow an attacker to cause the product to operate on unauthorized files.

CVSS

Оценка Severity Версия Базовый вектор
7.3 HIGH 3.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:L/A:H

EPSS

Вероятность Severity Процентиль ? Дата расчёта
0.22% LOW 12.64 30.08.2026

Доп. Информация

Product Status

Red Hat Container Native Virtualization 4.13
Product: Red Hat Container Native Virtualization 4.13
Vendor: Red Hat
Default status: affected
Версии:
Затронутые версии Статус
Наблюдалось в версиях от 1786346596 до * unaffected
СPE:
  • cpe:/a:redhat:container_native_virtualization:4.13::el9
Red Hat Container Native Virtualization 4.14
Product: Red Hat Container Native Virtualization 4.14
Vendor: Red Hat
Default status: affected
Версии:
Затронутые версии Статус
Наблюдалось в версиях от 1786309624 до * unaffected
СPE:
  • cpe:/a:redhat:container_native_virtualization:4.14::el9
Red Hat Container Native Virtualization 4.15
Product: Red Hat Container Native Virtualization 4.15
Vendor: Red Hat
Default status: affected
Версии:
Затронутые версии Статус
Наблюдалось в версиях от 1786347656 до * unaffected
СPE:
  • cpe:/a:redhat:container_native_virtualization:4.15::el9
Red Hat Container Native Virtualization 4.16
Product: Red Hat Container Native Virtualization 4.16
Vendor: Red Hat
Default status: affected
Версии:
Затронутые версии Статус
Наблюдалось в версиях от 1786030071 до * unaffected
СPE:
  • cpe:/a:redhat:container_native_virtualization:4.16::el9
Red Hat Container Native Virtualization 4.17
Product: Red Hat Container Native Virtualization 4.17
Vendor: Red Hat
Default status: affected
Версии:
Затронутые версии Статус
Наблюдалось в версиях от 1786348529 до * unaffected
СPE:
  • cpe:/a:redhat:container_native_virtualization:4.17::el9
Red Hat Container Native Virtualization 4.18
Product: Red Hat Container Native Virtualization 4.18
Vendor: Red Hat
Default status: affected
Версии:
Затронутые версии Статус
Наблюдалось в версиях от 1786130068 до * unaffected
СPE:
  • cpe:/a:redhat:container_native_virtualization:4.18::el9
Red Hat Container Native Virtualization 4.19
Product: Red Hat Container Native Virtualization 4.19
Vendor: Red Hat
Default status: affected
Версии:
Затронутые версии Статус
Наблюдалось в версиях от 1786334215 до * unaffected
СPE:
  • cpe:/a:redhat:container_native_virtualization:4.19::el9
Red Hat Container Native Virtualization 4.20
Product: Red Hat Container Native Virtualization 4.20
Vendor: Red Hat
Default status: affected
Версии:
Затронутые версии Статус
Наблюдалось в версиях от 1785831334 до * unaffected
СPE:
  • cpe:/a:redhat:container_native_virtualization:4.20::el9
Red Hat Container Native Virtualization 4.21
Product: Red Hat Container Native Virtualization 4.21
Vendor: Red Hat
Default status: affected
Версии:
Затронутые версии Статус
Наблюдалось в версиях от 1785829701 до * unaffected
СPE:
  • cpe:/a:redhat:container_native_virtualization:4.21::el9
Red Hat Container Native Virtualization 4.22
Product: Red Hat Container Native Virtualization 4.22
Vendor: Red Hat
Default status: affected
Версии:
Затронутые версии Статус
Наблюдалось в версиях от 1785140336 до * unaffected
СPE:
  • cpe:/a:redhat:container_native_virtualization:4.22::el9
Red Hat OpenShift Virtualization 4
Product: Red Hat OpenShift Virtualization 4
Vendor: Red Hat
Default status: affected
СPE:
  • cpe:/a:redhat:container_native_virtualization:4
 

Ссылки

CISA ADP Vulnrichment

Обновлено: 25.06.2026
Этот блок содержит дополнительную информацию, предоставленную программой CVE для этой уязвимости.

SSVC

Exploitation Automatable Technical Impact Версия Дата доступа
none no partial 2.0.3 25.06.2026

Мы используем cookie-файлы, чтобы получить статистику, которая помогает нам улучшить сервис для вас с целью персонализации сервисов и предложений. Вы может прочитать подробнее о cookie-файлах или изменить настройки браузера. Продолжая пользоваться сайтом, вы даёте согласие на использование ваших cookie-файлов и соглашаетесь с Политикой обработки персональных данных.