PT-2026-52088 · Kubevirt · Kubevirt
CVSS v3.1
6.5
Medium
| Vector | AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
KubeVirt (affected versions not specified)
Description
A flaw exists in the KubeVirt virt-handler domain notify server. The gRPC handlers
HandleDomainEvent() and HandleK8SEvent() determine the VMI identity (namespace/name) based only on the request body, failing to validate it against the connection origin. Because no identity tag is propagated from the per-VMI pipe socket used by each virt-launcher pod to the server handlers, a compromised virt-launcher process can send forged domain lifecycle events for any other VMI on the same node. This leads to the virt-handler incorrectly updating the state of the targeted VMI and disrupting its lifecycle management.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Improper Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Kubevirt