CVE-2025-64436

KubeVirt is a virtual machine management add-on for Kubernetes. In 1.5.0 and earlier, the permissions granted to the virt-handler service account, such as the ability to update VMI and patch nodes, could be abused to force a VMI migration to an attacker-controlled node. This vulnerability could otherwise allow an attacker to mark all nodes as unschedulable, potentially forcing the migration or creation of privileged pods onto a compromised node.
References
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:kubevirt:kubevirt:*:*:*:*:*:kubernetes:*:*
cpe:2.3:a:kubevirt:kubevirt:*:*:*:*:*:kubernetes:*:*

History

No history.

Information

Published : 2025-11-07 23:15

Updated : 2025-11-25 17:17


NVD link : CVE-2025-64436

Mitre link : CVE-2025-64436

CVE.ORG link : CVE-2025-64436


JSON object : View

Products Affected

kubevirt

  • kubevirt
CWE
CWE-269

Improper Privilege Management

CWE-276

Incorrect Default Permissions