KubeVirt is a virtual machine management add-on for Kubernetes. In 1.5.0 and earlier, the permissions granted to the virt-handler service account, such as the ability to update VMI and patch nodes, could be abused to force a VMI migration to an attacker-controlled node. This vulnerability could otherwise allow an attacker to mark all nodes as unschedulable, potentially forcing the migration or creation of privileged pods onto a compromised node.
Metrics
Affected Vendors & Products
References
History
Fri, 07 Nov 2025 23:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | KubeVirt is a virtual machine management add-on for Kubernetes. In 1.5.0 and earlier, the permissions granted to the virt-handler service account, such as the ability to update VMI and patch nodes, could be abused to force a VMI migration to an attacker-controlled node. This vulnerability could otherwise allow an attacker to mark all nodes as unschedulable, potentially forcing the migration or creation of privileged pods onto a compromised node. | |
| Title | KubeVirt Excessive Role Permissions Could Enable Unauthorized VMI Migrations Between Nodes | |
| Weaknesses | CWE-269 CWE-276 |
|
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: GitHub_M
Published: 2025-11-07T22:59:47.228Z
Updated: 2025-11-07T22:59:47.228Z
Reserved: 2025-11-03T22:12:51.365Z
Link: CVE-2025-64436
No data.
Status : Received
Published: 2025-11-07T23:15:46.003
Modified: 2025-11-07T23:15:46.003
Link: CVE-2025-64436
No data.