REDHAT-BUG-2493378: Medium severity Kubevirt migration proxy (pkg/virt-handler/migration-proxy/migration-proxy.go) vulnerability

Published Jun 26, 2026
·
Updated

A flaw was found in KubeVirt's migration proxy (pkg/virt-handler/migration-proxy/migration-proxy.go). When spec.configuration.migrations.disableTLS is set to true on the KubeVirt CR, serverTLSConfig is nilled and createTcpListener falls through to a plain net.Listen("tcp", ...) with no authentication. The listener binds unconditionally on 0.0.0.0/:: via GetIPZeroAddress() (pkg/util/net/ip/ip.go). The accept handler (handleConnection) performs no peer-IP check, no auth token validation, and immediately starts io.Copy into the target UNIX socket. The first proxied socket is virtqemud-sock, configured with authunixrw=none. Any pod on the cluster network can connect and speak libvirt RPC against another tenant's VM.

The migrations.network NAD configuration only changes the advertised migrationIpAddress (pkg/virt-handler/migration.go), not the listener bind, so the port remains reachable on the pod network even with a dedicated migration network. The API godoc (staging/src/kubevirt.io/api/core/v1/types.go) describes disableTLS as removing "the additional layer of live migration encryption" without disclosing the authentication removal. disableTLS is cluster-admin-only on the KubeVirt CR and is not available in the MigrationPolicy spec.

Affected Software

1 affected component
Kubevirt migration proxy (pkg/virt-handler/migration-proxy/migration-proxy.go)

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Configuration

    Do not set spec.configuration.migrations.disableTLS=true on the KubeVirt CR; when disableTLS is true it nils serverTLSConfig and createTcpListener uses plain net.Listen(...) with no authentication.

    KubeVirt spec.configuration.migrations.disableTLS = false
  2. Configuration

    Ensure the proxied virtqemud-sock is not configured with auth_unix_rw=none; configure Unix-RPC socket authentication so libvirt RPC cannot be issued cross-tenant without auth.

    KubeVirt migration proxy (pkg/virt-handler/migration-proxy/migration-proxy.go) virtqemud-sock auth_unix_rw = enabled (not 'none')
  3. Compensating control

    Restrict network access to the migration proxy listener so only pods/nodes on the dedicated migration network can reach it (the listener binds unconditionally on 0.0.0.0/:: and the migrations.network NAD only changes advertised migrationIpAddress, not the bind).

Event History

Jun 26, 2026
Data Sourced
via Red Hat·10:18 AM
DescriptionSeverityAffected Software
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of REDHAT-BUG-2493378?

The severity of REDHAT-BUG-2493378 is classified as medium, rated at 4.

2

What software is affected by REDHAT-BUG-2493378?

The vulnerability affects the KubeVirt migration proxy found in pkg/virt-handler/migration-proxy/migration-proxy.go.

3

How does REDHAT-BUG-2493378 affect security?

The flaw allows for a lack of authentication when TLS is disabled, potentially exposing communication to unauthorized access.

4

How can I mitigate the risk associated with REDHAT-BUG-2493378?

To mitigate this risk, ensure that spec.configuration.migrations.disableTLS is set to false in the KubeVirt CR to maintain TLS authentication.

5

What is the main issue identified in REDHAT-BUG-2493378?

The main issue is that when TLS is disabled, the migration proxy falls back to an unsecured TCP listener without proper authentication.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203