<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 18:14:25 +0000</lastBuildDate>
    <item>
      <title>certfr-2025-avi-1064 — De multiples vulnérabilités ont été découvertes dans les produits Microsoft. Certaines d'entre elles permettent à un at…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2025-avi-1064</link>
      <description>certfr-2025-avi-1064</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2025-avi-1064</guid>
    </item>
    <item>
      <title>EUVD-2026-271290</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-271290</link>
      <description>EUVD-2026-271290</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-271290</guid>
    </item>
    <item>
      <title>fkie_cve-2025-64324</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2025-64324</link>
      <description>&lt;p&gt;KubeVirt is a virtual machine management add-on for Kubernetes. The `hostDisk` feature in KubeVirt allows mounting a host file or directory owned by the user with UID 107 into a VM. However, prior to version 1.6.1 and 1.7.0, the implementation of this feature and more specifically the `DiskOrCreate` option (which creates a file if it doesn&amp;#39;t exist) has a logic bug that allows an attacker to read and write arbitrary files owned by more privileged users on the host system. Versions 1.6.1 and 1.7.0 fix the issue.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;KubeVirt is a virtual machine management add-on for Kubernetes. The `hostDisk` feature in KubeVirt allows mounting a host file or directory owned by the user with UID 107 into a VM. However, prior to version 1.6.1 and 1.7.0, the implementation of this feature and more specifically the `DiskOrCreate` option (which creates a file if it doesn&amp;#39;t exist) has a logic bug that allows an attacker to read and write arbitrary files owned by more privileged users on the host system. Versions 1.6.1 and 1.7.0 fix the issue.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2025-64324</guid>
    </item>
    <item>
      <title>GHSA-46xp-26xh-hpqh — KubeVirt Vulnerable to Arbitrary Host File Read and Write</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-46xp-26xh-hpqh</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: kubevirt.io/kubevirt&lt;/p&gt;
&lt;p&gt;### Summary
The `hostDisk` feature in KubeVirt allows mounting a host file or directory owned by the user with UID 107 into a VM. However, the implementation of this feature and more specifically the `DiskOrCreate` option which creates a file if it doesn&amp;#39;t exist, has a logic bug that allows an attacker to read and write arbitrary files owned by more privileged users on the host system.&lt;/p&gt;
&lt;p&gt;### Details
The `hostDisk` feature gate in KubeVirt allows mounting a QEMU RAW image directly from the host into a VM. While similar features, such as mounting disk images from a PVC, enforce ownership-based restrictions (e.g., only allowing files owned by specific UID, this mechanism can be subverted. For a RAW disk image to be readable by the QEMU process running within the `virt-launcher` pod, it must be owned by a user with UID 107. **If this ownership check is considered a security barrier, it can be bypassed**. In addition, the ownership of the host files mounted via this feature is changed to the user with UID 107.&lt;/p&gt;
&lt;p&gt;The above is due to a logic bug in the code of the `virt-handler` component which prepares and sets the permissions of the volumes and data inside which are going to be mounted in the `virt-launcher` pod and consecutively consumed by the VM. It is triggered when one tries to mount a host file or directory using the `DiskOrCreate` option. The relevant code is as follows:&lt;/p&gt;
&lt;p&gt;```go
// pkg/host-disk/host-disk.go&lt;/p&gt;
&lt;p&gt;func (hdc DiskImgCreator) Create(vmi *v1.VirtualMachineInstance)…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: kubevirt.io/kubevirt&lt;/p&gt;
&lt;p&gt;### Summary
The `hostDisk` feature in KubeVirt allows mounting a host file or directory owned by the user with UID 107 into a VM. However, the implementation of this feature and more specifically the `DiskOrCreate` option which creates a file if it doesn&amp;#39;t exist, has a logic bug that allows an attacker to read and write arbitrary files owned by more privileged users on the host system.&lt;/p&gt;
&lt;p&gt;### Details
The `hostDisk` feature gate in KubeVirt allows mounting a QEMU RAW image directly from the host into a VM. While similar features, such as mounting disk images from a PVC, enforce ownership-based restrictions (e.g., only allowing files owned by specific UID, this mechanism can be subverted. For a RAW disk image to be readable by the QEMU process running within the `virt-launcher` pod, it must be owned by a user with UID 107. **If this ownership check is considered a security barrier, it can be bypassed**. In addition, the ownership of the host files mounted via this feature is changed to the user with UID 107.&lt;/p&gt;
&lt;p&gt;The above is due to a logic bug in the code of the `virt-handler` component which prepares and sets the permissions of the volumes and data inside which are going to be mounted in the `virt-launcher` pod and consecutively consumed by the VM. It is triggered when one tries to mount a host file or directory using the `DiskOrCreate` option. The relevant code is as follows:&lt;/p&gt;
&lt;p&gt;```go
// pkg/host-disk/host-disk.go&lt;/p&gt;
&lt;p&gt;func (hdc DiskImgCreator) Create(vmi *v1.VirtualMachineInstance)…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-46xp-26xh-hpqh</guid>
    </item>
    <item>
      <title>msrc_CVE-2025-64324 — KubeVirt Vulnerable to Arbitrary Host File Read and Write</title>
      <link>https://cve.radiocsirt.org/vuln/msrc_cve-2025-64324</link>
      <description>msrc_CVE-2025-64324</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/msrc_cve-2025-64324</guid>
    </item>
    <item>
      <title>openSUSE-SU-2026:20281-1 — Security update for kubevirt</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2026:20281-1</link>
      <description>&lt;p&gt;Security update for kubevirt&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for kubevirt&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2026:20281-1</guid>
    </item>
    <item>
      <title>SUSE-SU-2026:20551-1 — Security update for kubevirt</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2026:20551-1</link>
      <description>&lt;p&gt;Security update for kubevirt&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for kubevirt&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2026:20551-1</guid>
    </item>
  </channel>
</rss>
