REDHAT-BUG-2543219: Medium severity Kubevirt virt-controller vulnerability

Published Sep 29, 2026
·
Updated

A flaw was found in KubeVirt's virt-controller. A namespace tenant with permission to create VirtualMachineInstance resources can submit a VMI with an empty ephemeral volume specification (ephemeral: {}). The admission webhook validates that the Ephemeral field is non-nil but does not check the inner PersistentVolumeClaim pointer, which defaults to nil as an optional field. When virt-controller processes this VMI, the rendervolumes code dereferences the nil PersistentVolumeClaim pointer, causing a panic. Because the Kubernetes crash handler re-panics by default and the malformed VMI persists in etcd, the controller enters a permanent crash loop, blocking all VM lifecycle operations cluster-wide until an administrator manually deletes the offending VMI.

Affected Software

1 affected component
Kubevirt virt-controller

Event History

Sep 29, 2026
Data Sourced
via Red Hat·02:45 PM
DescriptionSeverityAffected Software

Frequently Asked Questions

1

Who can trigger the controller crash loop?

A tenant in any namespace who has permission to create VirtualMachineInstance resources can trigger it by submitting a malformed VMI. No broader cluster-administration permission is described as necessary.

2

What malformed configuration causes the failure?

The VMI must include an empty ephemeral volume specification, expressed as ephemeral: {}. This leaves the optional inner PersistentVolumeClaim pointer nil, which passes admission validation but is later dereferenced by virt-controller.

3

What is the operational impact once exploitation succeeds?

virt-controller enters a persistent crash loop because the malformed VMI remains stored in etcd and is processed again after restart. This blocks VM lifecycle operations across the cluster.

4

What can administrators do if the controller is already crash-looping?

Manually delete the offending malformed VMI. Removing it prevents virt-controller from repeatedly processing the nil PersistentVolumeClaim pointer.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203