Red Hat Security Advisory: OpenShift Virtualization v4.21 Images
🔗 CVE IDs covered (3)
📋 Description
CVE-2026-13201 — kubevirt: virt-handler-rhel9: kubevirt: safepath symlink following in virt-handler enables notify socket hijacking and node-level VM disruption CVE-2026-13622 — kubevirt: virt-handler-rhel9: kubevirt: virt-handler migration proxy follows symlinks allowing container escape to host CVE-2026-33186 — google.golang.org/grpc/grpc-go: google.golang.org/grpc/authz: gRPC-Go: Authorization bypass due to improper HTTP/2 path validation
🎯 Affected products43
- Red Hat Container Native Virtualization 4.21
- registry.redhat.io/container-native-virtualization/libguestfs-tools-rhel9@sha256:4bf86c788191a8d81cf0659752510469c999c676fad359ef790c8c5ad9add216_amd64 as a component of Red Hat Container Native Virtualization 4.21
- registry.redhat.io/container-native-virtualization/libguestfs-tools-rhel9@sha256:da35e3474aefdd42b58d4e9498df8a348162c682804d5d61ac8e50aeaa3b2b98_arm64 as a component of Red Hat Container Native Virtualization 4.21
- registry.redhat.io/container-native-virtualization/libguestfs-tools-rhel9@sha256:f9f4560f8c8b7461ccdffc712ab05ac7accd0222e32cbf322030f7efacdd0752_s390x as a component of Red Hat Container Native Virtualization 4.21
- registry.redhat.io/container-native-virtualization/passt-network-binding-plugin-cni-rhel9@sha256:2d575188efd31a74486322d84e84e62c0dd6a2ee542db8cd3ad8c99b7cd9f7d3_arm64 as a component of Red Hat Container Native Virtualization 4.21
- registry.redhat.io/container-native-virtualization/passt-network-binding-plugin-cni-rhel9@sha256:2e9f6b38bbf4e6a48c4b936b4b5eb116be237f507f017345e1f7ca79ebdc7a15_amd64 as a component of Red Hat Container Native Virtualization 4.21
- registry.redhat.io/container-native-virtualization/passt-network-binding-plugin-cni-rhel9@sha256:9044ead847df9b0a56d0f4aeaa6d9052c0d69e57f20555aa0981605752aee375_s390x as a component of Red Hat Container Native Virtualization 4.21
- registry.redhat.io/container-native-virtualization/passt-network-binding-plugin-sidecar-rhel9@sha256:1446ba7d65f480a5036e528dad8ae7126b604423ea1cb6fb626ceab4d21a644b_arm64 as a component of Red Hat Container Native Virtualization 4.21
- registry.redhat.io/container-native-virtualization/passt-network-binding-plugin-sidecar-rhel9@sha256:1ec852eb243c7ce9244887ecce91f42801f88efd91f314de1524ed89f601f9fe_amd64 as a component of Red Hat Container Native Virtualization 4.21
- registry.redhat.io/container-native-virtualization/passt-network-binding-plugin-sidecar-rhel9@sha256:279df5ddd149cd31ca26dae46e154410ba3394b3e72488de19e1112c9bf84e70_s390x as a component of Red Hat Container Native Virtualization 4.21
- registry.redhat.io/container-native-virtualization/pr-helper-rhel9@sha256:581e2109e7a5953761984290f10e84a478bd75bc73b5d900b5956ddc319ef315_arm64 as a component of Red Hat Container Native Virtualization 4.21
- registry.redhat.io/container-native-virtualization/pr-helper-rhel9@sha256:769969f04a3c4bdd964720db6784a86402305c58d16aea45d11294b388eea32a_s390x as a component of Red Hat Container Native Virtualization 4.21
- registry.redhat.io/container-native-virtualization/pr-helper-rhel9@sha256:98187476f1fa8fa9c91663ccb64995d77e880c47d44d3930ab642a71baed3923_amd64 as a component of Red Hat Container Native Virtualization 4.21
- registry.redhat.io/container-native-virtualization/sidecar-shim-rhel9@sha256:36a8ac5f07d563a8e3fe8ab1499e7e3966c4ae352981dc0e857cbf6a880f579f_arm64 as a component of Red Hat Container Native Virtualization 4.21
- registry.redhat.io/container-native-virtualization/sidecar-shim-rhel9@sha256:3c9095ca3261e747f5735ba2bd50e19e3c638ed22e01aa6310d993ef13c7c39a_s390x as a component of Red Hat Container Native Virtualization 4.21
- registry.redhat.io/container-native-virtualization/sidecar-shim-rhel9@sha256:a915d646b8b62d50b00ad020ccc0f108bd0d7ffa25bcd61df28b1afa1c4728df_amd64 as a component of Red Hat Container Native Virtualization 4.21
- registry.redhat.io/container-native-virtualization/virt-api-rhel9@sha256:43f112bebd52d117d69a03a343ff4eeeca46e02371523b87eb710740a1d5c47e_arm64 as a component of Red Hat Container Native Virtualization 4.21
- registry.redhat.io/container-native-virtualization/virt-api-rhel9@sha256:867646b237904d2808d847f56c66917ba796c6095c1a28a0272df1c084695ea7_amd64 as a component of Red Hat Container Native Virtualization 4.21
- registry.redhat.io/container-native-virtualization/virt-api-rhel9@sha256:f5d6ec45cba17236c5d9b14bb0de46fd3970020bd4d3cc9529017379a7d7b867_s390x as a component of Red Hat Container Native Virtualization 4.21
- registry.redhat.io/container-native-virtualization/virt-artifacts-server-rhel9@sha256:8517080f3b37b9ac0eca41f7c2298a7ac273c6ade123a54edd38ed2956b58480_s390x as a component of Red Hat Container Native Virtualization 4.21
- registry.redhat.io/container-native-virtualization/virt-artifacts-server-rhel9@sha256:8af23e4ed67b50a6232d3a4276226e2a9bc957e067a96047fcfcaf6df017a0ef_amd64 as a component of Red Hat Container Native Virtualization 4.21
- registry.redhat.io/container-native-virtualization/virt-artifacts-server-rhel9@sha256:98f9b5b0ee258e562a751f27bb68b7edb49e50f9e9febe3297a1892331264ffb_arm64 as a component of Red Hat Container Native Virtualization 4.21
- registry.redhat.io/container-native-virtualization/virt-controller-rhel9@sha256:32fb284469021d61a0c9161ad272c7e1a7b7d855f559ceafbc9f2015e5f1b9fa_amd64 as a component of Red Hat Container Native Virtualization 4.21
- registry.redhat.io/container-native-virtualization/virt-controller-rhel9@sha256:c98085fbcc4fb39353b662a5ac3b641b0dcf4c224fc90d01060fc67097b7d855_s390x as a component of Red Hat Container Native Virtualization 4.21
- registry.redhat.io/container-native-virtualization/virt-controller-rhel9@sha256:ecc15205fcb67e4ed55401617cd3a310880c0220fb347891c7f74a764f2968c4_arm64 as a component of Red Hat Container Native Virtualization 4.21
- registry.redhat.io/container-native-virtualization/virt-exportproxy-rhel9@sha256:5f97f71d3c8654e6728203276d1e348cc3ab38c85ad1f8f971afb3882cc2509c_arm64 as a component of Red Hat Container Native Virtualization 4.21
- registry.redhat.io/container-native-virtualization/virt-exportproxy-rhel9@sha256:8968223352116fe4e3c01301eaa399303746a2ca052c06e3680ddf6452a4326a_s390x as a component of Red Hat Container Native Virtualization 4.21
- registry.redhat.io/container-native-virtualization/virt-exportproxy-rhel9@sha256:bdc0ee85eaf2ce54ff4933086306350dc52aa39eb3a3b5bbda52d0dab04441ad_amd64 as a component of Red Hat Container Native Virtualization 4.21
- registry.redhat.io/container-native-virtualization/virt-exportserver-rhel9@sha256:1eef40bdfc3b353816016f9c2047313a16f566cd6be51cd613123147981317f0_amd64 as a component of Red Hat Container Native Virtualization 4.21
- registry.redhat.io/container-native-virtualization/virt-exportserver-rhel9@sha256:4ef6cfdb1d3e85bd7579dc7874e03882b638de56fffd9eecd2cb33b854ee89c1_arm64 as a component of Red Hat Container Native Virtualization 4.21
- +13 more not shown
✅ Remediation
Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258 Workaround: The following measures reduce the attacker pool and limit secondary impact: Review RBAC policies to restrict pods/exec permissions on virt-launcher pods to only those users who strictly require it. This reduces the number of identities that can place symlinks in the launcher filesystem. Ensure SELinux is in enforcing mode (default in OpenShift). While SELinux does not prevent the notify socket hijacking path, it restricts the set of host files targetable through the chown/chmod path by blocking operations on files with protected security labels. RHCOS immutable filesystem layers prevent modification of core OS files through the chown/chmod path. Note: no mitigation currently addresses the notify socket hijacking vector. The attacker's ability to inject domain events into virt-handler is not constrained by SELinux or filesystem immutability. Workaround: Restrict pods/exec permissions in namespaces that run virtual machines. The pods/exec RBAC permission is required for the attack — removing it from VM operator roles prevents exploitation. Additionally, enable Kubernetes audit logging and monitor for kubectl exec commands targeting virt-launcher pods, especially during live migration events. Workaround: To mitigate this issue, implement infrastructure-level normalization to ensure all incoming HTTP/2 `:path` headers are properly formatted with a leading slash before reaching the gRPC-Go server. This can be achieved by configuring a reverse proxy or API gateway to validate and normalize the `:path` header. Ensure that any such intermediary is properly configured and restarted to apply the changes, which may temporarily impact service availability.
🔗 References (6)
- selfhttps://access.redhat.com/errata/RHSA-2026:53728
- externalhttps://access.redhat.com/security/cve/CVE-2026-13201
- externalhttps://access.redhat.com/security/cve/CVE-2026-13622
- externalhttps://access.redhat.com/security/cve/CVE-2026-33186
- externalhttps://access.redhat.com/security/updates/classification/
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_53728.json