{"id":"AZL-95943","summary":"CVE-2026-13622 affecting package kubevirt 1.8.4-1","details":"A symlink following vulnerability was found in KubeVirt's virt-handler migration proxy. During live migration, virt-handler dials Unix sockets inside the target virt-launcher pod via /proc/\u003cpid\u003e/root/ paths using net.Dial() without symlink protection. These socket paths reside in qemu-owned directories writable by the virt-launcher user. An attacker with namespace edit and pods/exec permissions can replace a migration proxy socket with a symlink to the host CRI-O socket. Because virt-handler runs as root in the host mount namespace, absolute symlink targets resolve against the host filesystem, and the bidirectional io.Copy proxy relays attacker-controlled bytes to the container runtime, enabling full node compromise.","modified":"2026-09-20T05:33:47Z","published":"2026-08-12T21:17:35Z","upstream":["CVE-2026-13622"],"references":[{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-13622"}],"affected":[{"package":{"name":"kubevirt","ecosystem":"Azure Linux:3","purl":"pkg:rpm/azure-linux/kubevirt"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"last_affected":"1.8.4-1"}]}],"database_specific":{"source":"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-95943.json"}}],"schema_version":"1.9.0"}