CVE-2025-64437 Details
Description
KubeVirt is a virtual machine management add-on for Kubernetes. In versions before 1.5.3 and 1.6.1, the virt-handler does not verify whether the launcher-sock is a symlink or a regular file. This oversight can be exploited, for example, to change the ownership of arbitrary files on the host node to the unprivileged user with UID 107 (the same user used by virt-launcher) thus, compromising the CIA (Confidentiality, Integrity and Availability) of data on the host. To successfully exploit this vulnerability, an attacker should be in control of the file system of the virt-launcher pod. This vulnerability is fixed in 1.5.3 and 1.6.1.
A vulnerability exists in KubeVirt's virt-handler component, specifically in versions prior to 1.5.3 and 1.6.1. The issue arises because virt-handler does not properly verify whether the launcher-sock is a symlink or a regular file. This flaw can be exploited to change the ownership of arbitrary files on the host node to an unprivileged user with UID 107, which is the same user used by virt-launcher. As a result, this vulnerability can compromise the confidentiality, integrity, and availability of data on the host. To exploit this vulnerability, an attacker must have control over the file system of the virt-launcher pod.
Users can upgrade to KubeVirt versions 1.5.3 or 1.6.1, where this vulnerability has been fixed.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Nov 10, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-59 | Improper Link Resolution Before File Access ('Link Following') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| kubevirt kubevirt | < 1.5.3 1.6.0 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Nov 25, 2025 | Initial Analysis | [email protected] |
| Nov 7, 2025 | New CVE Received | [email protected] |