<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 20:55:51 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-260467</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-260467</link>
      <description>EUVD-2026-260467</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-260467</guid>
    </item>
    <item>
      <title>fkie_cve-2025-64437</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2025-64437</link>
      <description>&lt;p&gt;KubeVirt is a virtual machine management add-on for Kubernetes. In versions before 1.5.3 and 1.6.1, the virt-handler does not verify whether the launcher-sock is a symlink or a regular file. This oversight can be exploited, for example, to change the ownership of arbitrary files on the host node to the unprivileged user with UID 107 (the same user used by virt-launcher) thus, compromising the CIA (Confidentiality, Integrity and Availability) of data on the host. To successfully exploit this vulnerability, an attacker should be in control of the file system of the virt-launcher pod. This vulnerability is fixed in 1.5.3 and 1.6.1.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;KubeVirt is a virtual machine management add-on for Kubernetes. In versions before 1.5.3 and 1.6.1, the virt-handler does not verify whether the launcher-sock is a symlink or a regular file. This oversight can be exploited, for example, to change the ownership of arbitrary files on the host node to the unprivileged user with UID 107 (the same user used by virt-launcher) thus, compromising the CIA (Confidentiality, Integrity and Availability) of data on the host. To successfully exploit this vulnerability, an attacker should be in control of the file system of the virt-launcher pod. This vulnerability is fixed in 1.5.3 and 1.6.1.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2025-64437</guid>
    </item>
    <item>
      <title>GHSA-2r4r-5x78-mvqf — KubeVirt Isolation Detection Flaw Allows Arbitrary File Permission Changes</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-2r4r-5x78-mvqf</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: kubevirt.io/kubevirt&lt;/p&gt;
&lt;p&gt;### Summary
_Short summary of the problem. Make the impact and severity as clear as possible.&lt;/p&gt;
&lt;p&gt;It is possible to trick the `virt-handler` component into changing the ownership of arbitrary files on the host node to the unprivileged user with UID `107` due to mishandling of symlinks when determining the root mount of a `virt-launcher` pod.&lt;/p&gt;
&lt;p&gt;### Details
_Give all details on the vulnerability. Pointing to the incriminated source code is very helpful for the maintainer._&lt;/p&gt;
&lt;p&gt;In the current implementation, the `virt-handler` does not verify whether the `launcher-sock` is a symlink or a regular file. This oversight can be exploited, for example, to change the ownership of arbitrary files on the host node to the unprivileged user with UID `107` (the same user used by `virt-launcher`) thus, compromising the CIA (Confidentiality, Integrity and Availability) of data on the host. 
To successfully exploit this vulnerability, an attacker should be in control of the file system of the `virt-launcher` pod.&lt;/p&gt;
&lt;p&gt;### PoC
_Complete instructions, including specific configuration details, to reproduce the vulnerability._&lt;/p&gt;
&lt;p&gt;In this demonstration, two additional vulnerabilities are combined with the primary issue to arbitrarily change the ownership of a file located on the host node:&lt;/p&gt;
&lt;p&gt;1. A symbolic link (`launcher-sock`) is used to manipulate the interpretation of the root mount within the affected container, effectively bypassing expected isolation boundaries.
2. Another symbolic link (`disk.img`) is…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: kubevirt.io/kubevirt&lt;/p&gt;
&lt;p&gt;### Summary
_Short summary of the problem. Make the impact and severity as clear as possible.&lt;/p&gt;
&lt;p&gt;It is possible to trick the `virt-handler` component into changing the ownership of arbitrary files on the host node to the unprivileged user with UID `107` due to mishandling of symlinks when determining the root mount of a `virt-launcher` pod.&lt;/p&gt;
&lt;p&gt;### Details
_Give all details on the vulnerability. Pointing to the incriminated source code is very helpful for the maintainer._&lt;/p&gt;
&lt;p&gt;In the current implementation, the `virt-handler` does not verify whether the `launcher-sock` is a symlink or a regular file. This oversight can be exploited, for example, to change the ownership of arbitrary files on the host node to the unprivileged user with UID `107` (the same user used by `virt-launcher`) thus, compromising the CIA (Confidentiality, Integrity and Availability) of data on the host. 
To successfully exploit this vulnerability, an attacker should be in control of the file system of the `virt-launcher` pod.&lt;/p&gt;
&lt;p&gt;### PoC
_Complete instructions, including specific configuration details, to reproduce the vulnerability._&lt;/p&gt;
&lt;p&gt;In this demonstration, two additional vulnerabilities are combined with the primary issue to arbitrarily change the ownership of a file located on the host node:&lt;/p&gt;
&lt;p&gt;1. A symbolic link (`launcher-sock`) is used to manipulate the interpretation of the root mount within the affected container, effectively bypassing expected isolation boundaries.
2. Another symbolic link (`disk.img`) is…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-2r4r-5x78-mvqf</guid>
    </item>
    <item>
      <title>msrc_CVE-2025-64437 — KubeVirt Isolation Detection Flaw Allows Arbitrary File Permission Changes</title>
      <link>https://cve.radiocsirt.org/vuln/msrc_cve-2025-64437</link>
      <description>msrc_CVE-2025-64437</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/msrc_cve-2025-64437</guid>
    </item>
    <item>
      <title>openSUSE-SU-2025:15772-1 — kubevirt-container-disk-1.6.3-1.1 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2025:15772-1</link>
      <description>&lt;p&gt;kubevirt-container-disk-1.6.3-1.1 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;kubevirt-container-disk-1.6.3-1.1 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2025:15772-1</guid>
    </item>
    <item>
      <title>SUSE-SU-2026:20551-1 — Security update for kubevirt</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2026:20551-1</link>
      <description>&lt;p&gt;Security update for kubevirt&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for kubevirt&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2026:20551-1</guid>
    </item>
    <item>
      <title>WID-SEC-W-2025-2563 — Microsoft Azure Linux: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2025-2563</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Microsoft Azure Linux und Microsoft Windows ausnutzen um erhöhte Privilegien zu erlangen, beliebigen Code auszuführen, die Authentifizierung zu umgehen,  Spoofing-Angriffe durchzuführen, einen Denial-of-Service-Zustand zu verursachen oder andere, nicht näher spezifizierte Angriffe durchzuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Microsoft Azure Linux und Microsoft Windows ausnutzen um erhöhte Privilegien zu erlangen, beliebigen Code auszuführen, die Authentifizierung zu umgehen,  Spoofing-Angriffe durchzuführen, einen Denial-of-Service-Zustand zu verursachen oder andere, nicht näher spezifizierte Angriffe durchzuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2025-2563</guid>
    </item>
  </channel>
</rss>
