<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-04T14:36:50.723393+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-260468</id>
    <title>EUVD-2026-260468</title>
    <updated>2026-10-04T14:36:50.728021+00:00</updated>
    <content>EUVD-2026-260468</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-260468"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2025-64436</id>
    <title>fkie_cve-2025-64436</title>
    <updated>2026-10-04T14:36:50.728077+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>KubeVirt is a virtual machine management add-on for Kubernetes. In 1.5.0 and earlier, the permissions granted to the virt-handler service account, such as the ability to update VMI and patch nodes, could be abused to force a VMI migration to an attacker-controlled node. This vulnerability could otherwise allow an attacker to mark all nodes as unschedulable, potentially forcing the migration or creation of privileged pods onto a compromised node.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2025-64436"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-7xgm-5prm-v5gc</id>
    <title>GHSA-7xgm-5prm-v5gc — KubeVirt Excessive Role Permissions Could Enable Unauthorized VMI Migrations Between Nodes</title>
    <updated>2026-10-04T14:36:50.728133+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Go: kubevirt.io/kubevirt</p>
<p>### Summary</p>
<p>The permissions granted to the `virt-handler` service account, such as the ability to update VMI and patch nodes, could be abused to force a VMI migration to an attacker-controlled node.</p>
<p>### Details</p>
<p>Following the [GitHub security advisory published on March 23 2023](https://github.com/kubevirt/kubevirt/security/advisories/GHSA-cp96-jpmq-xrr2), a `ValidatingAdmissionPolicy` was introduced to impose restrictions on which sections of node resources the `virt-handler` service account can modify. For instance, the `spec` section of nodes has been made immutable, and modifications to the `labels` section are now limited to `kubevirt.io`-prefixed labels only. This vulnerability could otherwise allow an attacker to mark all nodes as unschedulable, potentially forcing the migration or creation of privileged pods onto a compromised node.</p>
<p>However, if a `virt-handler` service account is compromised, either through the pod itself or the underlying node, an attacker may still modify node labels, both on the compromised node and on other nodes within the cluster. Notably, `virt-handler` sets a specific `kubevirt.io` boolean label, `kubevirt.io/schedulable`, which indicates whether the node can host VMI workloads. An attacker could repeatedly patch other nodes by setting this label to `false`, thereby forcing all #acr("vmi") instances to be scheduled exclusively on the compromised node.</p>
<p>[Another finding](https://github.com/kubevirt/kubevirt/security/advisories/GHSA-ggp9-c9…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-7xgm-5prm-v5gc"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/msrc_cve-2025-64436</id>
    <title>msrc_CVE-2025-64436 — KubeVirt Excessive Role Permissions Could Enable Unauthorized VMI Migrations Between Nodes</title>
    <updated>2026-10-04T14:36:50.728264+00:00</updated>
    <content>msrc_CVE-2025-64436</content>
    <link href="https://cve.radiocsirt.org/vuln/msrc_cve-2025-64436"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2025-2563</id>
    <title>WID-SEC-W-2025-2563 — Microsoft Azure Linux: Mehrere Schwachstellen</title>
    <updated>2026-10-04T14:36:50.728298+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein Angreifer kann mehrere Schwachstellen in Microsoft Azure Linux und Microsoft Windows ausnutzen um erhöhte Privilegien zu erlangen, beliebigen Code auszuführen, die Authentifizierung zu umgehen,  Spoofing-Angriffe durchzuführen, einen Denial-of-Service-Zustand zu verursachen oder andere, nicht näher spezifizierte Angriffe durchzuführen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2025-2563"/>
  </entry>
</feed>
