CVE-2026-13622: Kubevirt: virt-handler-rhel9: kubevirt: virt-handler migration proxy follows symlinks allowing container escape to host

Published Jun 29, 2026
·
Updated

A symlink following vulnerability was found in KubeVirt's virt-handler migration proxy. During live migration, the target-side virt-handler uses net.Dial("unix", "/proc/<pid>/root/...") to connect to Unix sockets inside the target virt-launcher pod. This call follows symlinks without restriction. The socket directories (/var/run/kubevirt/migrationproxy/, /var/run/libvirt/) are owned by the qemu user and writable from within the container. An authenticated user with namespace edit and pods/exec can trigger a migration, exec into the target virt-launcher, replace a socket with a symlink to the host CRI-O socket, and proxy arbitrary CRI gRPC from the source launcher — achieving full node compromise.

Other sources

A symlink following vulnerability was found in KubeVirt's virt-handler migration proxy. During live migration, virt-handler dials Unix sockets inside the target virt-launcher pod via /proc/<pid>/root/ paths using net.Dial() without symlink protection. These socket paths reside in qemu-owned directories writable by the virt-launcher user. An attacker with namespace edit and pods/exec permissions can replace a migration proxy socket with a symlink to the host CRI-O socket. Because virt-handler runs as root in the host mount namespace, absolute symlink targets resolve against the host filesystem, and the bidirectional io.Copy proxy relays attacker-controlled bytes to the container runtime, enabling full node compromise.

MITRE

Affected Software

2 affected components
Kubevirt virt-handler-rhel9
Kubevirt virt-handler migration proxy

Event History

Jun 29, 2026
Data Sourced
via Red Hat·10:11 AM
DescriptionSeverityAffected Software
Aug 12, 2026
CVE Published
via MITRE·08:46 PM
Data Sourced
via MITRE·08:46 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·09:17 PM
DescriptionSeverityWeakness
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2026-13622?

CVE-2026-13622 has a high severity rating of 8.8.

2

What does CVE-2026-13622 affect?

CVE-2026-13622 affects the Kubevirt virt-handler migration proxy.

3

How do I fix CVE-2026-13622?

To mitigate CVE-2026-13622, you should apply the latest patches or updates for Kubevirt that address this symlink following vulnerability.

4

What type of vulnerability is CVE-2026-13622?

CVE-2026-13622 is a path traversal vulnerability that allows container escape to the host.

5

When was CVE-2026-13622 published?

CVE-2026-13622 was published on August 12, 2026.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203