<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-04T01:44:02.884158+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2025-avi-1064</id>
    <title>certfr-2025-avi-1064 — De multiples vulnérabilités ont été découvertes dans les produits Microsoft. Certaines d'entre elles permettent à un at…</title>
    <updated>2026-10-04T01:44:02.994046+00:00</updated>
    <content>certfr-2025-avi-1064</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2025-avi-1064"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-271290</id>
    <title>EUVD-2026-271290</title>
    <updated>2026-10-04T01:44:02.994085+00:00</updated>
    <content>EUVD-2026-271290</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-271290"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2025-64324</id>
    <title>fkie_cve-2025-64324</title>
    <updated>2026-10-04T01:44:02.994101+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>KubeVirt is a virtual machine management add-on for Kubernetes. The `hostDisk` feature in KubeVirt allows mounting a host file or directory owned by the user with UID 107 into a VM. However, prior to version 1.6.1 and 1.7.0, the implementation of this feature and more specifically the `DiskOrCreate` option (which creates a file if it doesn't exist) has a logic bug that allows an attacker to read and write arbitrary files owned by more privileged users on the host system. Versions 1.6.1 and 1.7.0 fix the issue.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2025-64324"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-46xp-26xh-hpqh</id>
    <title>GHSA-46xp-26xh-hpqh — KubeVirt Vulnerable to Arbitrary Host File Read and Write</title>
    <updated>2026-10-04T01:44:02.994132+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Go: kubevirt.io/kubevirt</p>
<p>### Summary
The `hostDisk` feature in KubeVirt allows mounting a host file or directory owned by the user with UID 107 into a VM. However, the implementation of this feature and more specifically the `DiskOrCreate` option which creates a file if it doesn't exist, has a logic bug that allows an attacker to read and write arbitrary files owned by more privileged users on the host system.</p>
<p>### Details
The `hostDisk` feature gate in KubeVirt allows mounting a QEMU RAW image directly from the host into a VM. While similar features, such as mounting disk images from a PVC, enforce ownership-based restrictions (e.g., only allowing files owned by specific UID, this mechanism can be subverted. For a RAW disk image to be readable by the QEMU process running within the `virt-launcher` pod, it must be owned by a user with UID 107. **If this ownership check is considered a security barrier, it can be bypassed**. In addition, the ownership of the host files mounted via this feature is changed to the user with UID 107.</p>
<p>The above is due to a logic bug in the code of the `virt-handler` component which prepares and sets the permissions of the volumes and data inside which are going to be mounted in the `virt-launcher` pod and consecutively consumed by the VM. It is triggered when one tries to mount a host file or directory using the `DiskOrCreate` option. The relevant code is as follows:</p>
<p>```go
// pkg/host-disk/host-disk.go</p>
<p>func (hdc DiskImgCreator) Create(vmi *v1.VirtualMachineInstance)…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-46xp-26xh-hpqh"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/msrc_cve-2025-64324</id>
    <title>msrc_CVE-2025-64324 — KubeVirt Vulnerable to Arbitrary Host File Read and Write</title>
    <updated>2026-10-04T01:44:02.994206+00:00</updated>
    <content>msrc_CVE-2025-64324</content>
    <link href="https://cve.radiocsirt.org/vuln/msrc_cve-2025-64324"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2026:20281-1</id>
    <title>openSUSE-SU-2026:20281-1 — Security update for kubevirt</title>
    <updated>2026-10-04T01:44:02.994224+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for kubevirt</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2026:20281-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2026:20551-1</id>
    <title>SUSE-SU-2026:20551-1 — Security update for kubevirt</title>
    <updated>2026-10-04T01:44:02.994243+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for kubevirt</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2026:20551-1"/>
  </entry>
</feed>
