{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/kubevirt/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":8.8,"id":"CVE-2026-13622"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["KubeVirt"],"_cs_severities":["high"],"_cs_tags":["kubernetes","cloud","privilege-escalation","container-security"],"_cs_type":"advisory","_cs_vendors":["KubeVirt"],"content_html":"\u003cp\u003eCVE-2026-13622 is a critical privilege escalation vulnerability identified in the KubeVirt virt-handler migration proxy. The flaw resides in the migration logic where virt-handler dials Unix sockets within a target virt-launcher pod using paths constructed via /proc/\u0026lt;pid\u0026gt;/root/. Because the implementation fails to enforce symlink protection during this process, an attacker who has already obtained pod/exec or namespace edit permissions can manipulate the socket environment.\u003c/p\u003e\n\u003cp\u003eThe vulnerability is compounded by the fact that virt-handler executes with root privileges within the host mount namespace. By replacing a legitimate migration proxy socket with a symlink pointing to sensitive host-level sockets, such as the CRI-O socket, an attacker can trick the proxy into relaying traffic to the container runtime. This effectively allows the attacker to execute unauthorized commands at the node level, leading to a complete compromise of the underlying host.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker gains initial access to a Kubernetes namespace with pod/exec and permissions to modify pod resources.\u003c/li\u003e\n\u003cli\u003eAttacker locates the qemu-owned directory within the target virt-launcher pod where migration sockets reside.\u003c/li\u003e\n\u003cli\u003eAttacker removes or renames the legitimate migration proxy socket file.\u003c/li\u003e\n\u003cli\u003eAttacker creates a malicious symlink at the original socket path, pointing the target to the host's CRI-O socket located at /var/run/crio/crio.sock.\u003c/li\u003e\n\u003cli\u003eAttacker triggers a live migration event within the KubeVirt environment to force virt-handler to initiate a connection.\u003c/li\u003e\n\u003cli\u003evirt-handler, running as root in the host mount namespace, follows the symlink and connects to the CRI-O socket.\u003c/li\u003e\n\u003cli\u003evirt-handler uses io.Copy to bridge the connection, allowing the attacker to relay malicious container runtime commands through the proxy.\u003c/li\u003e\n\u003cli\u003eHost-level container runtime processes the relayed commands, granting the attacker control over the node.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of CVE-2026-13622 results in a total loss of confidentiality, integrity, and availability for the affected KubeVirt node. Attackers can escape the container context to gain root access to the host machine, potentially leading to unauthorized access to all pods running on the compromised node, exfiltration of node-level secrets, and disruption of cluster operations.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003ePatch KubeVirt immediately to the latest version that includes the fix for CVE-2026-13622.\u003c/li\u003e\n\u003cli\u003eReview Kubernetes RBAC policies to restrict 'pods/exec' and namespace modification permissions to the absolute minimum necessary personnel.\u003c/li\u003e\n\u003cli\u003eImplement Pod Security Admissions or admission controllers to prevent unauthorized modification of sensitive container file paths.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-12T22:52:48Z","date_published":"2026-08-12T22:52:48Z","id":"https://feed.craftedsignal.io/briefs/2026-08-kubevirt-symlink-rce/","summary":"A symlink following vulnerability (CVE-2026-13622) in KubeVirt allows an attacker with pod execution permissions to escalate privileges and achieve full node compromise by redirecting migration proxy socket traffic.","title":"KubeVirt virt-handler Privilege Escalation via Symlink Injection","url":"https://feed.craftedsignal.io/briefs/2026-08-kubevirt-symlink-rce/"}],"language":"en","title":"CraftedSignal Threat Feed - KubeVirt","version":"https://jsonfeed.org/version/1.1"}