KubeVirt is a virtual machine management add-on for Kubernetes. In 1.5.0 and earlier, the permissions granted to the virt-handler service account, such as the ability to update VMI and patch nodes, could be abused to force a VMI migration to an attacker-controlled node. This vulnerability could otherwise allow an attacker to mark all nodes as unschedulable, potentially forcing the migration or creation of privileged pods onto a compromised node.
History

Fri, 07 Nov 2025 23:15:00 +0000

Type Values Removed Values Added
Description KubeVirt is a virtual machine management add-on for Kubernetes. In 1.5.0 and earlier, the permissions granted to the virt-handler service account, such as the ability to update VMI and patch nodes, could be abused to force a VMI migration to an attacker-controlled node. This vulnerability could otherwise allow an attacker to mark all nodes as unschedulable, potentially forcing the migration or creation of privileged pods onto a compromised node.
Title KubeVirt Excessive Role Permissions Could Enable Unauthorized VMI Migrations Between Nodes
Weaknesses CWE-269
CWE-276
References
Metrics cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published: 2025-11-07T22:59:47.228Z

Updated: 2025-11-07T22:59:47.228Z

Reserved: 2025-11-03T22:12:51.365Z

Link: CVE-2025-64436

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2025-11-07T23:15:46.003

Modified: 2025-11-07T23:15:46.003

Link: CVE-2025-64436

cve-icon Redhat

No data.