Home

Description

A flaw was found in KubeVirt's virt-handler component. This vulnerability allows an authenticated OpenShift user with edit permissions in a single namespace to exploit improper symlink validation when connecting to virtual machine console sockets. By replacing the console socket with a symlink to the host's container runtime (CRI-O) socket, an attacker can hijack virt-handler's privileged connection. This enables the attacker to access any Unix socket on the host, potentially leading to full control of the node and the entire cluster.

PUBLISHED Reserved 2026-04-29 | Published 2026-05-26 | Updated 2026-05-28 | Assigner redhat




CRITICAL: 9.9CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

Problem types

Improper Link Resolution Before File Access ('Link Following')

Product status

Default status
affected

1779375376 (rpm) before *
unaffected

Default status
affected

1778999881 (rpm) before *
unaffected

Default status
affected

1779321599 (rpm) before *
unaffected

Default status
affected

1778859977 (rpm) before *
unaffected

Default status
affected

1778861274 (rpm) before *
unaffected

Default status
affected

1779174925 (rpm) before *
unaffected

Default status
affected

1778887155 (rpm) before *
unaffected

Default status
affected

1779289071 (rpm) before *
unaffected

Default status
affected

1779288737 (rpm) before *
unaffected

Default status
affected

1779420069 (rpm) before *
unaffected

Timeline

2026-04-22:Reported to Red Hat.
2026-05-26:Made public.

Credits

This issue was discovered by Sarah Bennert (Red Hat) and Stoyan Nikolov (Red Hat).

References

access.redhat.com/errata/RHSA-2026:20720 (RHSA-2026:20720) vendor-advisory

access.redhat.com/errata/RHSA-2026:20736 (RHSA-2026:20736) vendor-advisory

access.redhat.com/errata/RHSA-2026:20763 (RHSA-2026:20763) vendor-advisory

access.redhat.com/errata/RHSA-2026:20767 (RHSA-2026:20767) vendor-advisory

access.redhat.com/errata/RHSA-2026:20782 (RHSA-2026:20782) vendor-advisory

access.redhat.com/errata/RHSA-2026:20825 (RHSA-2026:20825) vendor-advisory

access.redhat.com/errata/RHSA-2026:20866 (RHSA-2026:20866) vendor-advisory

access.redhat.com/errata/RHSA-2026:20886 (RHSA-2026:20886) vendor-advisory

access.redhat.com/errata/RHSA-2026:20890 (RHSA-2026:20890) vendor-advisory

access.redhat.com/errata/RHSA-2026:20975 (RHSA-2026:20975) vendor-advisory

access.redhat.com/security/cve/CVE-2026-7374 vdb-entry

bugzilla.redhat.com/show_bug.cgi?id=2463728 (RHBZ#2463728) issue-tracking

cve.org (CVE-2026-7374)

nvd.nist.gov (CVE-2026-7374)

Download JSON