REDHAT-BUG-2463728: High severity Kubevirt virt-handler vulnerability
A flaw was found in KubeVirt's virt-handler component. virt-handler connects to VM console sockets by following filesystem paths without validating symlinks. An authenticated OpenShift user with the standard edit role in a single namespace can exec into the virt-launcher pod, replace the console socket with a symlink pointing to the host's container runtime (CRI-O) socket, and hijack virt-handler's privileged connection. Since virt-handler runs with hostPID and elevated privileges, this allows the attacker to reach any unix socket on the host, potentially gaining full control of the node and cluster.
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-2463728?
The severity of REDHAT-BUG-2463728 is categorized as high with a score of 7.
How do I fix REDHAT-BUG-2463728?
To fix REDHAT-BUG-2463728, ensure that appropriate validation is implemented for symlinks in the virt-handler component.
What vulnerabilities does REDHAT-BUG-2463728 introduce?
REDHAT-BUG-2463728 introduces a security risk that allows authenticated OpenShift users to potentially gain unauthorized access to VM console sockets.
Who is affected by REDHAT-BUG-2463728?
Authenticated OpenShift users with the standard edit role in a single namespace are primarily affected by REDHAT-BUG-2463728.
What component is involved in REDHAT-BUG-2463728?
The flaw in REDHAT-BUG-2463728 involves the virt-handler component of KubeVirt.