CVE-2026-7374

Summary

A flaw was found in KubeVirt's virt-handler component. This vulnerability allows an authenticated OpenShift user with edit permissions in a single namespace to exploit improper symlink validation when connecting to virtual machine console sockets. By replacing the console socket with a symlink to the host's container runtime (CRI-O) socket, an attacker can hijack virt-handler's privileged connection. This enables the attacker to access any Unix socket on the host, potentially leading to full control of the node and the entire cluster.

Affected Software

VendorProductVersion RangeStatus
0 < 1.6.6affected
1.7.0 < 1.7.4affected
1.8.0 < 1.8.3affected
Red HatRed Hat Container Native Virtualization 4.121779375376 < *unaffected
Red HatRed Hat Container Native Virtualization 4.131778999881 < *unaffected
Red HatRed Hat Container Native Virtualization 4.141779321599 < *unaffected
Red HatRed Hat Container Native Virtualization 4.151778859977 < *unaffected
Red HatRed Hat Container Native Virtualization 4.161778861274 < *unaffected
Red HatRed Hat Container Native Virtualization 4.171779174925 < *unaffected
Red HatRed Hat Container Native Virtualization 4.181778887155 < *unaffected
Red HatRed Hat Container Native Virtualization 4.191779289071 < *unaffected
Red HatRed Hat Container Native Virtualization 4.201779288737 < *unaffected
Red HatRed Hat Container Native Virtualization 4.211779420069 < *unaffected

Weaknesses

  • CWE-59: Improper Link Resolution Before File Access ('Link Following')

Workarounds

Update cluster RBAC to not allow exec into virt-launcher pods.

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: total

Additional References

References