<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 23:55:17 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-232063</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-232063</link>
      <description>EUVD-2026-232063</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-232063</guid>
    </item>
    <item>
      <title>fkie_cve-2022-1798</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2022-1798</link>
      <description>&lt;p&gt;A path traversal vulnerability in KubeVirt versions up to 0.56 (and 0.55.1) on all platforms allows a user able to configure the kubevirt to read arbitrary files on the host filesystem which are publicly readable or which are readable for UID 107 or GID 107. /proc/self/&amp;lt;&amp;gt; is not accessible.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A path traversal vulnerability in KubeVirt versions up to 0.56 (and 0.55.1) on all platforms allows a user able to configure the kubevirt to read arbitrary files on the host filesystem which are publicly readable or which are readable for UID 107 or GID 107. /proc/self/&amp;lt;&amp;gt; is not accessible.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2022-1798</guid>
    </item>
    <item>
      <title>Withdrawn: GHSA-cvx8-ppmc-78hm — Duplicate Advisory: KubeVirt arbitrary host file read from the VM</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-cvx8-ppmc-78hm</link>
      <description>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: kubevirt.io/kubevirt&lt;/p&gt;
&lt;p&gt;## Duplicate Advisory
This advisory is a duplicate of [GHSA-qv98-3369-g364](https://github.com/advisories/GHSA-qv98-3369-g364). This link is maintained to preserve external references.&lt;/p&gt;
&lt;p&gt;## Original Description&lt;/p&gt;
&lt;p&gt;**Summary**
As part of a Kubevirt audit performed by NCC group, a finding dealing with systemic lack of path sanitization which leads to a path traversal was identified.  Google tested the exploitability of the paths in the audit report and identified that when combined with another vulnerability one of the paths leads to an arbitrary file read on the host from the VM.&lt;/p&gt;
&lt;p&gt;The read operations are limited to files which are publicly readable or which are readable for UID 107 or GID 107. /proc/self/&amp;lt;&amp;gt; is not accessible.&lt;/p&gt;
&lt;p&gt;**Severity**&lt;/p&gt;
&lt;p&gt;Moderate - The vulnerability is proven to exist in an open source version of KubeVirt by NCC Group while being combined with Systemic Lack of Path Sanitization, which leads to Path traversal.&lt;/p&gt;
&lt;p&gt;**Proof of Concept**&lt;/p&gt;
&lt;p&gt;The initial VMI specifications can be written as such to reproduce the issue:&lt;/p&gt;
&lt;p&gt;```&lt;/p&gt;
&lt;p&gt;apiVersion: kubevirt.io/v1
kind: VirtualMachineInstance
metadata:
  name: vmi-fedora
spec:
  domain:
    devices:
      disks:
      - disk:
          bus: virtio
        name: containerdisk
      - disk:
          bus: virtio
        name: cloudinitdisk
      - disk:
          bus: virtio
        name: containerdisk1
      rng: {}
    resources:
      requests:
        memory: 1024M
  terminationGracePeriodSeconds: 0
  volumes:
  - containerDisk:…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: kubevirt.io/kubevirt&lt;/p&gt;
&lt;p&gt;## Duplicate Advisory
This advisory is a duplicate of [GHSA-qv98-3369-g364](https://github.com/advisories/GHSA-qv98-3369-g364). This link is maintained to preserve external references.&lt;/p&gt;
&lt;p&gt;## Original Description&lt;/p&gt;
&lt;p&gt;**Summary**
As part of a Kubevirt audit performed by NCC group, a finding dealing with systemic lack of path sanitization which leads to a path traversal was identified.  Google tested the exploitability of the paths in the audit report and identified that when combined with another vulnerability one of the paths leads to an arbitrary file read on the host from the VM.&lt;/p&gt;
&lt;p&gt;The read operations are limited to files which are publicly readable or which are readable for UID 107 or GID 107. /proc/self/&amp;lt;&amp;gt; is not accessible.&lt;/p&gt;
&lt;p&gt;**Severity**&lt;/p&gt;
&lt;p&gt;Moderate - The vulnerability is proven to exist in an open source version of KubeVirt by NCC Group while being combined with Systemic Lack of Path Sanitization, which leads to Path traversal.&lt;/p&gt;
&lt;p&gt;**Proof of Concept**&lt;/p&gt;
&lt;p&gt;The initial VMI specifications can be written as such to reproduce the issue:&lt;/p&gt;
&lt;p&gt;```&lt;/p&gt;
&lt;p&gt;apiVersion: kubevirt.io/v1
kind: VirtualMachineInstance
metadata:
  name: vmi-fedora
spec:
  domain:
    devices:
      disks:
      - disk:
          bus: virtio
        name: containerdisk
      - disk:
          bus: virtio
        name: cloudinitdisk
      - disk:
          bus: virtio
        name: containerdisk1
      rng: {}
    resources:
      requests:
        memory: 1024M
  terminationGracePeriodSeconds: 0
  volumes:
  - containerDisk:…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-cvx8-ppmc-78hm</guid>
    </item>
    <item>
      <title>gsd-2022-1798</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2022-1798</link>
      <description>gsd-2022-1798</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2022-1798</guid>
    </item>
    <item>
      <title>msrc_CVE-2022-1798 — Path Traversal vulnerability in Kubevirt</title>
      <link>https://cve.radiocsirt.org/vuln/msrc_cve-2022-1798</link>
      <description>msrc_CVE-2022-1798</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/msrc_cve-2022-1798</guid>
    </item>
    <item>
      <title>RHSA-2022:6351 — Red Hat Security Advisory: OpenShift Virtualization 4.10.5 Images security and bug fix update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2022:6351</link>
      <description>&lt;p&gt;kubeVirt: Arbitrary file read on the host from KubeVirt VMs go-restful: Authorization Bypass Through User-Controlled Key&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;kubeVirt: Arbitrary file read on the host from KubeVirt VMs go-restful: Authorization Bypass Through User-Controlled Key&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2022:6351</guid>
    </item>
    <item>
      <title>SUSE-SU-2022:3321-1 — Security update for kubevirt, virt-api-container, virt-controller-container, virt-handler-container, virt-launcher-cont…</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2022:3321-1</link>
      <description>&lt;p&gt;Security update for kubevirt, virt-api-container, virt-controller-container, virt-handler-container, virt-launcher-container, virt-libguestfs-tools-container, virt-operator-container&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for kubevirt, virt-api-container, virt-controller-container, virt-handler-container, virt-launcher-container, virt-libguestfs-tools-container, virt-operator-container&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2022:3321-1</guid>
    </item>
    <item>
      <title>WID-SEC-W-2022-1312 — Red Hat OpenShift: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2022-1312</link>
      <description>&lt;p&gt;Ein entfernter, anonymer oder authentisierter Angreifer kann mehrere Schwachstellen in Red Hat OpenShift ausnutzen, um Informationen offenzulegen und Sicherheitsmaßnahmen zu umgehen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, anonymer oder authentisierter Angreifer kann mehrere Schwachstellen in Red Hat OpenShift ausnutzen, um Informationen offenzulegen und Sicherheitsmaßnahmen zu umgehen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2022-1312</guid>
    </item>
  </channel>
</rss>
