<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 06:07:55 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-260469</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-260469</link>
      <description>EUVD-2026-260469</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-260469</guid>
    </item>
    <item>
      <title>fkie_cve-2025-64435</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2025-64435</link>
      <description>&lt;p&gt;KubeVirt is a virtual machine management add-on for Kubernetes. Prior to 1.7.0-beta.0, a logic flaw in the virt-controller allows an attacker to disrupt the control over a running VMI by creating a pod with the same labels as the legitimate virt-launcher pod associated with the VMI. This can mislead the virt-controller into associating the fake pod with the VMI, resulting in incorrect status updates and potentially causing a DoS (Denial-of-Service). This vulnerability is fixed in 1.7.0-beta.0.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;KubeVirt is a virtual machine management add-on for Kubernetes. Prior to 1.7.0-beta.0, a logic flaw in the virt-controller allows an attacker to disrupt the control over a running VMI by creating a pod with the same labels as the legitimate virt-launcher pod associated with the VMI. This can mislead the virt-controller into associating the fake pod with the VMI, resulting in incorrect status updates and potentially causing a DoS (Denial-of-Service). This vulnerability is fixed in 1.7.0-beta.0.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2025-64435</guid>
    </item>
    <item>
      <title>GHSA-9m94-w2vq-hcf9 — KubeVirt VMI Denial-of-Service (DoS) Using Pod Impersonation</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-9m94-w2vq-hcf9</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: kubevirt.io/kubevirt&lt;/p&gt;
&lt;p&gt;### Summary
_Short summary of the problem. Make the impact and severity as clear as possible.&lt;/p&gt;
&lt;p&gt;A logic flaw in the `virt-controller` allows an attacker to disrupt the control over a running VMI by creating a pod with the same labels as the legitimate `virt-launcher` pod associated with the VMI. This can mislead the `virt-controller` into associating the fake pod with the VMI, resulting in incorrect status updates and potentially causing a DoS (Denial-of-Service).&lt;/p&gt;
&lt;p&gt;### Details
_Give all details on the vulnerability. Pointing to the incriminated source code is very helpful for the maintainer._&lt;/p&gt;
&lt;p&gt;A vulnerability has been identified in the logic responsible for reconciling the state of VMI. Specifically, it is possible to associate a malicious attacker-controlled pod with an existing VMI running within the same namespace as the pod, thereby replacing the legitimate `virt-launcher` pod associated with the VMI.&lt;/p&gt;
&lt;p&gt;The `virt-launcher` pod is critical for enforcing the isolation mechanisms applied to the QEMU process that runs the virtual machine. It also serves, along with `virt-handler`, as a management interface that allows cluster users, operators, or administrators to control the lifecycle of the VMI (e.g., starting, stopping, or migrating it).&lt;/p&gt;
&lt;p&gt;When `virt-controller` receives a notification about a change in a VMI&amp;#39;s state, it attempts to identify the corresponding `virt-launcher` pod. This is necessary in several scenarios, including:&lt;/p&gt;
&lt;p&gt;- When hardware devices are requested to be…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: kubevirt.io/kubevirt&lt;/p&gt;
&lt;p&gt;### Summary
_Short summary of the problem. Make the impact and severity as clear as possible.&lt;/p&gt;
&lt;p&gt;A logic flaw in the `virt-controller` allows an attacker to disrupt the control over a running VMI by creating a pod with the same labels as the legitimate `virt-launcher` pod associated with the VMI. This can mislead the `virt-controller` into associating the fake pod with the VMI, resulting in incorrect status updates and potentially causing a DoS (Denial-of-Service).&lt;/p&gt;
&lt;p&gt;### Details
_Give all details on the vulnerability. Pointing to the incriminated source code is very helpful for the maintainer._&lt;/p&gt;
&lt;p&gt;A vulnerability has been identified in the logic responsible for reconciling the state of VMI. Specifically, it is possible to associate a malicious attacker-controlled pod with an existing VMI running within the same namespace as the pod, thereby replacing the legitimate `virt-launcher` pod associated with the VMI.&lt;/p&gt;
&lt;p&gt;The `virt-launcher` pod is critical for enforcing the isolation mechanisms applied to the QEMU process that runs the virtual machine. It also serves, along with `virt-handler`, as a management interface that allows cluster users, operators, or administrators to control the lifecycle of the VMI (e.g., starting, stopping, or migrating it).&lt;/p&gt;
&lt;p&gt;When `virt-controller` receives a notification about a change in a VMI&amp;#39;s state, it attempts to identify the corresponding `virt-launcher` pod. This is necessary in several scenarios, including:&lt;/p&gt;
&lt;p&gt;- When hardware devices are requested to be…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-9m94-w2vq-hcf9</guid>
    </item>
    <item>
      <title>msrc_CVE-2025-64435 — KubeVirt VMI Denial-of-Service (DoS) Using Pod Impersonation</title>
      <link>https://cve.radiocsirt.org/vuln/msrc_cve-2025-64435</link>
      <description>msrc_CVE-2025-64435</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/msrc_cve-2025-64435</guid>
    </item>
    <item>
      <title>openSUSE-SU-2026:20281-1 — Security update for kubevirt</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2026:20281-1</link>
      <description>&lt;p&gt;Security update for kubevirt&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for kubevirt&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2026:20281-1</guid>
    </item>
    <item>
      <title>SUSE-SU-2026:20551-1 — Security update for kubevirt</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2026:20551-1</link>
      <description>&lt;p&gt;Security update for kubevirt&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for kubevirt&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2026:20551-1</guid>
    </item>
    <item>
      <title>WID-SEC-W-2025-2563 — Microsoft Azure Linux: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2025-2563</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Microsoft Azure Linux und Microsoft Windows ausnutzen um erhöhte Privilegien zu erlangen, beliebigen Code auszuführen, die Authentifizierung zu umgehen,  Spoofing-Angriffe durchzuführen, einen Denial-of-Service-Zustand zu verursachen oder andere, nicht näher spezifizierte Angriffe durchzuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Microsoft Azure Linux und Microsoft Windows ausnutzen um erhöhte Privilegien zu erlangen, beliebigen Code auszuführen, die Authentifizierung zu umgehen,  Spoofing-Angriffe durchzuführen, einen Denial-of-Service-Zustand zu verursachen oder andere, nicht näher spezifizierte Angriffe durchzuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2025-2563</guid>
    </item>
  </channel>
</rss>
