REDHAT-BUG-2493576: Input Validation

Published Jun 26, 2026
·
Updated

A flaw was found in KubeVirt's network annotation generator. The tenant-supplied multus.networkName in a VMI spec is written verbatim into the launcher pod's v1.multus-cni.io/default-network annotation without input validation. When the ExternalNetResourceInjection Beta feature gate is enabled (off by default), no NAD lookup is performed to catch malformed values, and a tenant can inject a JSON-formatted NetworkSelectionElement array to attach the pod to arbitrary network attachments in any namespace with attacker-controlled IP and MAC addresses. This enables cross-namespace network access and service impersonation. The vulnerable code path was introduced with the ExternalNetResourceInjection feature gate in KubeVirt v1.8.0, first shipped in OpenShift Virtualization 4.21.

Affected Software

1 affected component
Kubevirt network annotation generator>=1.8.0<=1.8.0

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade KubeVirt to a version that resolves this vulnerability.

    Fixed in 1.8.0
  2. Configuration

    Ensure the ExternalNetResourceInjection Beta feature gate remains disabled to prevent tenant-supplied multus.networkName from being written verbatim into the launcher pod annotation without input validation.

    KubeVirt feature gate ExternalNetResourceInjection = disabled (off by default)
  3. Compensating control

    If the ExternalNetResourceInjection Beta feature gate must be enabled, restrict tenant ability to set multus.networkName in VMI specs (e.g., via admission controls/policy) to mitigate cross-namespace network access and service impersonation risks from attacker-controlled IP/MAC injection.

Event History

Jun 26, 2026
Data Sourced
via Red Hat·03:15 PM
DescriptionSeverityAffected Software
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of REDHAT-BUG-2493576?

The severity of REDHAT-BUG-2493576 is medium with a risk rating of 4.

2

What does REDHAT-BUG-2493576 entail?

REDHAT-BUG-2493576 describes a flaw in KubeVirt's network annotation generator that lacks input validation for tenant-supplied multus.networkName.

3

How do I fix REDHAT-BUG-2493576?

To fix REDHAT-BUG-2493576, ensure proper input validation is implemented for multus.networkName in the VMI spec.

4

Which software is affected by REDHAT-BUG-2493576?

The affected software in REDHAT-BUG-2493576 is KubeVirt's network annotation generator.

5

What is the impact of REDHAT-BUG-2493576?

The impact of REDHAT-BUG-2493576 is that it could allow improper network configuration due to lack of input validation.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203