CVE-2026-13325: Virt-handler-rhel9: kubevirt: kubevirt: disabletls migration setting removes authentication, exposing unauthenticated virtqemud proxy on all interfaces
A flaw was found in KubeVirt's migration proxy (pkg/virt-handler/migration-proxy/migration-proxy.go). When spec.configuration.migrations.disableTLS is set to true on the KubeVirt CR, serverTLSConfig is nilled and createTcpListener falls through to a plain net.Listen("tcp", ...) with no authentication. The listener binds unconditionally on 0.0.0.0/:: via GetIPZeroAddress() (pkg/util/net/ip/ip.go). The accept handler (handleConnection) performs no peer-IP check, no auth token validation, and immediately starts io.Copy into the target UNIX socket. The first proxied socket is virtqemud-sock, configured with authunixrw=none. Any pod on the cluster network can connect and speak libvirt RPC against another tenant's VM.
The migrations.network NAD configuration only changes the advertised migrationIpAddress (pkg/virt-handler/migration.go), not the listener bind, so the port remains reachable on the pod network even with a dedicated migration network. The API godoc (staging/src/kubevirt.io/api/core/v1/types.go) describes disableTLS as removing "the additional layer of live migration encryption" without disclosing the authentication removal. disableTLS is cluster-admin-only on the KubeVirt CR and is not available in the MigrationPolicy spec.
Other sources
Rejected reason: Red Hat Product Security has come to the conclusion that this CVE is not needed.
— NVD
Virt-handler-rhel9: kubevirt: kubevirt: disabletls migration setting removes authentication, exposing unauthenticated virtqemud proxy on all interfaces
— Microsoft
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Configuration
On the KubeVirt custom resource, set spec.configuration.migrations.disableTLS to false so serverTLSConfig is not nilled and the virt-handler migration proxy does not fall through to a plain net.Listen with no authentication.
KubeVirt CR (spec.configuration.migrations.disableTLS) spec.configuration.migrations.disableTLS = false - Compensating control
Restrict network access to the virt-handler migration-proxy listener (bound unconditionally via GetIPZeroAddress() to 0.0.0.0/::) so only the intended migration network/pods can reach the proxy port (e.g., enforce firewall/NetworkPolicy/ACL rules limiting inbound connections to the migration-proxy listener).
Event History
Frequently Asked Questions
What is the severity of CVE-2026-13325?
The severity of CVE-2026-13325 is rated as high with a score of 8.5.
How do I fix CVE-2026-13325?
To fix CVE-2026-13325, avoid setting the spec.configuration.migrations.disableTLS to true in KubeVirt configurations.
What impact does CVE-2026-13325 have on my systems?
CVE-2026-13325 exposes an unauthenticated virtqemud proxy on all interfaces, leading to potential unauthorized access.
Which software is affected by CVE-2026-13325?
CVE-2026-13325 affects the KubeVirt migration proxy known as virt-handler.
When was CVE-2026-13325 published?
CVE-2026-13325 was published on June 26, 2026.