CVE-2026-13218: Kubevirt: kubevirt: symlink following in writetocachedfile allows host file overwrite from virt-launcher

Published Jun 25, 2026
·
Updated

A flaw was found in KubeVirt's network cache handling in virt-handler. The WriteToCachedFile function in pkg/network/cache/cache.go writes network cache data to a path under /proc/<launcherPid>/root/var/run/kubevirt-private/ using os.WriteFile and then changes ownership using os.Chown. Neither operation uses ONOFOLLOW or the safepath package to prevent symlink traversal. Since virt-handler operates in the host mount namespace (only the network namespace is entered via setns), a symlink planted by a compromised virt-launcher process at the cache file path causes virt-handler to follow the symlink and write to an arbitrary host file, overwriting its content with JSON data and changing its ownership to uid 107. This constitutes a container-to-host file write primitive, though with constrained content (serialized JSON network cache data). The vulnerable code path is triggered only for bridge/non-masquerade interfaces (via the discoverbridge path in vm.go -> netconf.go -> cache.go). The default masquerade binding does not exercise this path.

Other sources

A flaw was found in KubeVirt's virt-handler network cache handling. The WriteToCachedFile function writes data to a launcher-rooted path using os.WriteFile and os.Chown without symlink protection. A user with access to the virt-launcher container can plant a symlink at the cache file path, causing virt-handler to follow it and overwrite an arbitrary host file with JSON content and change its ownership.

MITRE

Affected Software

3 affected components
Kubevirt virt-handler
Kubevirt Kubevirt Kubernetes
redhat Openshift Virtualization>=4<=4.22.0

Event History

Jun 25, 2026
Data Sourced
via Red Hat·07:54 AM
DescriptionSeverityAffected Software
CVE Published
via MITRE·11:23 PM
Data Sourced
via MITRE·11:23 PM
DescriptionSeverityWeakness
Jun 26, 2026
Data Sourced
via NVD·12:16 AM
DescriptionSeverityWeaknessAffected Software
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2026-13218?

The severity of CVE-2026-13218 is classified as medium with a score of 4.2.

2

What does CVE-2026-13218 impact?

CVE-2026-13218 impacts KubeVirt's virt-handler network cache handling.

3

How can I mitigate CVE-2026-13218?

To mitigate CVE-2026-13218, avoid granting unnecessary access to the virt-launcher container.

4

What is the main issue described in CVE-2026-13218?

The main issue in CVE-2026-13218 is a flaw in the WriteToCachedFile function that allows symlink following, leading to potential host file overwriting.

5

Who is affected by CVE-2026-13218?

Users with access to the virt-launcher container are affected by CVE-2026-13218.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203