<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T07:04:28.069413+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-260467</id>
    <title>EUVD-2026-260467</title>
    <updated>2026-10-03T07:04:28.153527+00:00</updated>
    <content>EUVD-2026-260467</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-260467"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2025-64437</id>
    <title>fkie_cve-2025-64437</title>
    <updated>2026-10-03T07:04:28.153566+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>KubeVirt is a virtual machine management add-on for Kubernetes. In versions before 1.5.3 and 1.6.1, the virt-handler does not verify whether the launcher-sock is a symlink or a regular file. This oversight can be exploited, for example, to change the ownership of arbitrary files on the host node to the unprivileged user with UID 107 (the same user used by virt-launcher) thus, compromising the CIA (Confidentiality, Integrity and Availability) of data on the host. To successfully exploit this vulnerability, an attacker should be in control of the file system of the virt-launcher pod. This vulnerability is fixed in 1.5.3 and 1.6.1.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2025-64437"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-2r4r-5x78-mvqf</id>
    <title>GHSA-2r4r-5x78-mvqf — KubeVirt Isolation Detection Flaw Allows Arbitrary File Permission Changes</title>
    <updated>2026-10-03T07:04:28.153601+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Go: kubevirt.io/kubevirt</p>
<p>### Summary
_Short summary of the problem. Make the impact and severity as clear as possible.</p>
<p>It is possible to trick the `virt-handler` component into changing the ownership of arbitrary files on the host node to the unprivileged user with UID `107` due to mishandling of symlinks when determining the root mount of a `virt-launcher` pod.</p>
<p>### Details
_Give all details on the vulnerability. Pointing to the incriminated source code is very helpful for the maintainer._</p>
<p>In the current implementation, the `virt-handler` does not verify whether the `launcher-sock` is a symlink or a regular file. This oversight can be exploited, for example, to change the ownership of arbitrary files on the host node to the unprivileged user with UID `107` (the same user used by `virt-launcher`) thus, compromising the CIA (Confidentiality, Integrity and Availability) of data on the host. 
To successfully exploit this vulnerability, an attacker should be in control of the file system of the `virt-launcher` pod.</p>
<p>### PoC
_Complete instructions, including specific configuration details, to reproduce the vulnerability._</p>
<p>In this demonstration, two additional vulnerabilities are combined with the primary issue to arbitrarily change the ownership of a file located on the host node:</p>
<p>1. A symbolic link (`launcher-sock`) is used to manipulate the interpretation of the root mount within the affected container, effectively bypassing expected isolation boundaries.
2. Another symbolic link (`disk.img`) is…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-2r4r-5x78-mvqf"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/msrc_cve-2025-64437</id>
    <title>msrc_CVE-2025-64437 — KubeVirt Isolation Detection Flaw Allows Arbitrary File Permission Changes</title>
    <updated>2026-10-03T07:04:28.153671+00:00</updated>
    <content>msrc_CVE-2025-64437</content>
    <link href="https://cve.radiocsirt.org/vuln/msrc_cve-2025-64437"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2025:15772-1</id>
    <title>openSUSE-SU-2025:15772-1 — kubevirt-container-disk-1.6.3-1.1 on GA media</title>
    <updated>2026-10-03T07:04:28.153690+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>kubevirt-container-disk-1.6.3-1.1 on GA media</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2025:15772-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2026:20551-1</id>
    <title>SUSE-SU-2026:20551-1 — Security update for kubevirt</title>
    <updated>2026-10-03T07:04:28.153707+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for kubevirt</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2026:20551-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2025-2563</id>
    <title>WID-SEC-W-2025-2563 — Microsoft Azure Linux: Mehrere Schwachstellen</title>
    <updated>2026-10-03T07:04:28.153724+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein Angreifer kann mehrere Schwachstellen in Microsoft Azure Linux und Microsoft Windows ausnutzen um erhöhte Privilegien zu erlangen, beliebigen Code auszuführen, die Authentifizierung zu umgehen,  Spoofing-Angriffe durchzuführen, einen Denial-of-Service-Zustand zu verursachen oder andere, nicht näher spezifizierte Angriffe durchzuführen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2025-2563"/>
  </entry>
</feed>
