RHSA-2026:53763HighCVSS 9.1

Red Hat Security Advisory: OpenShift Virtualization v4.20 Images

Published
August 11, 2026
Last Modified
August 20, 2026

🔗 CVE IDs covered (3)

📋 Description

CVE-2026-13201 — kubevirt: virt-handler-rhel9: kubevirt: safepath symlink following in virt-handler enables notify socket hijacking and node-level VM disruption CVE-2026-13622 — kubevirt: virt-handler-rhel9: kubevirt: virt-handler migration proxy follows symlinks allowing container escape to host CVE-2026-33186 — google.golang.org/grpc/grpc-go: google.golang.org/grpc/authz: gRPC-Go: Authorization bypass due to improper HTTP/2 path validation

🎯 Affected products43

  • Red Hat Container Native Virtualization 4.20
  • registry.redhat.io/container-native-virtualization/libguestfs-tools-rhel9@sha256:5885a1074a3a65b4738e645330e859b598633099d07c752de587742c4910972c_s390x as a component of Red Hat Container Native Virtualization 4.20
  • registry.redhat.io/container-native-virtualization/libguestfs-tools-rhel9@sha256:b69427db5e3a68edfb5f733acb785e3a1eeccfc45cab8754e4f4c5106e5f5afe_arm64 as a component of Red Hat Container Native Virtualization 4.20
  • registry.redhat.io/container-native-virtualization/libguestfs-tools-rhel9@sha256:ca8bdcb57fbd508abd84a8f90ddf8814ba90c48260ab0487912cd73446e860b9_amd64 as a component of Red Hat Container Native Virtualization 4.20
  • registry.redhat.io/container-native-virtualization/passt-network-binding-plugin-cni-rhel9@sha256:035d9d574bbd049c8f78f6eb5e60e187b71c58338a7675d94af313b490fde55e_amd64 as a component of Red Hat Container Native Virtualization 4.20
  • registry.redhat.io/container-native-virtualization/passt-network-binding-plugin-cni-rhel9@sha256:8a18299a120af78a290db514378a79d0c92b98ab2f85c1b9c57380dae521445f_s390x as a component of Red Hat Container Native Virtualization 4.20
  • registry.redhat.io/container-native-virtualization/passt-network-binding-plugin-cni-rhel9@sha256:f670603d4d39f8e935bb699380a656ed411c3a9bab4e3cccc576cb5e2ca05a03_arm64 as a component of Red Hat Container Native Virtualization 4.20
  • registry.redhat.io/container-native-virtualization/passt-network-binding-plugin-sidecar-rhel9@sha256:0c5cb766e878638b908ef02dba80e7a8fa052f9bf5ed9524864d40f9643b7afc_s390x as a component of Red Hat Container Native Virtualization 4.20
  • registry.redhat.io/container-native-virtualization/passt-network-binding-plugin-sidecar-rhel9@sha256:1709a7d2d244242522129bbde3df1747f9bdbdf3864326ee8b433bbfc3739609_amd64 as a component of Red Hat Container Native Virtualization 4.20
  • registry.redhat.io/container-native-virtualization/passt-network-binding-plugin-sidecar-rhel9@sha256:e3ecb267c56c3cf6b1aeee43b675844546fd2dd3bbbec2d480ceca0044fd1d28_arm64 as a component of Red Hat Container Native Virtualization 4.20
  • registry.redhat.io/container-native-virtualization/pr-helper-rhel9@sha256:3c4564a91c58287af63e4640db353e42c843c3a12c0ff13321fee26046d8965e_amd64 as a component of Red Hat Container Native Virtualization 4.20
  • registry.redhat.io/container-native-virtualization/pr-helper-rhel9@sha256:8bcc028dcc826e11f1805d2a49b575a4e19524ce94827cc6748e661f6149329e_s390x as a component of Red Hat Container Native Virtualization 4.20
  • registry.redhat.io/container-native-virtualization/pr-helper-rhel9@sha256:aed9e1f8ef852872bc865e88dca4c7dd3c5b6850bfd6608d2339f831f14cf112_arm64 as a component of Red Hat Container Native Virtualization 4.20
  • registry.redhat.io/container-native-virtualization/sidecar-shim-rhel9@sha256:2484a6c137f63d51400a9eae1280d0732c6ff138f38b767e6630769a1a663752_arm64 as a component of Red Hat Container Native Virtualization 4.20
  • registry.redhat.io/container-native-virtualization/sidecar-shim-rhel9@sha256:a3834d4c533a619718fd30eaa7caf8f642d3f611dd38cc2e0896c8f45f4e1d64_s390x as a component of Red Hat Container Native Virtualization 4.20
  • registry.redhat.io/container-native-virtualization/sidecar-shim-rhel9@sha256:b50eb1aefdbacf6c44ea64bfa4769b21f5352ff455e7345a3a558fb797b325ba_amd64 as a component of Red Hat Container Native Virtualization 4.20
  • registry.redhat.io/container-native-virtualization/virt-api-rhel9@sha256:59002673312121d9446b2198c640ab8619c73b51daf6ea0ee83c0ed6e4d0e552_s390x as a component of Red Hat Container Native Virtualization 4.20
  • registry.redhat.io/container-native-virtualization/virt-api-rhel9@sha256:eaf455f757f4ae47efa9aab416cc49dfdf5bd6b380672c957554617dfcf8c263_arm64 as a component of Red Hat Container Native Virtualization 4.20
  • registry.redhat.io/container-native-virtualization/virt-api-rhel9@sha256:eed15c476ec896f6a78cd588c789c6ba2c7cadf924610fe56a147645beb0bf25_amd64 as a component of Red Hat Container Native Virtualization 4.20
  • registry.redhat.io/container-native-virtualization/virt-artifacts-server-rhel9@sha256:43ffd77478055bce8805d6581315c143eb5cd6f5eece252091cf5ce7262da23b_amd64 as a component of Red Hat Container Native Virtualization 4.20
  • registry.redhat.io/container-native-virtualization/virt-artifacts-server-rhel9@sha256:46be6670bbf26ca082095821c2701e2955255afd1e38ccdd9c14a71170e346ab_s390x as a component of Red Hat Container Native Virtualization 4.20
  • registry.redhat.io/container-native-virtualization/virt-artifacts-server-rhel9@sha256:6b7eeba222f54ce24528afcc14ab4fd4a0b62a05e284bb7533d859275e2b6252_arm64 as a component of Red Hat Container Native Virtualization 4.20
  • registry.redhat.io/container-native-virtualization/virt-controller-rhel9@sha256:4a466a7cfb37b925d1ef7c0f49624479e93127beffd120fb8fd0192dc44af9c8_s390x as a component of Red Hat Container Native Virtualization 4.20
  • registry.redhat.io/container-native-virtualization/virt-controller-rhel9@sha256:d9a57850eb1b31a01271c2b574ec2ecf88c05df555aac0ec67c6f7b41ca3c45a_amd64 as a component of Red Hat Container Native Virtualization 4.20
  • registry.redhat.io/container-native-virtualization/virt-controller-rhel9@sha256:dea4c39f0dcbb57384a1bb3b620fd116aad31ad226d9ab97c0568075b0890936_arm64 as a component of Red Hat Container Native Virtualization 4.20
  • registry.redhat.io/container-native-virtualization/virt-exportproxy-rhel9@sha256:02a31da1a264f0caf4db820db1f6423f769628cad7f6e4740d725b907725c129_s390x as a component of Red Hat Container Native Virtualization 4.20
  • registry.redhat.io/container-native-virtualization/virt-exportproxy-rhel9@sha256:18681858e47d4d2d169bf21bfacd943f0029a60bdf423664d5dd62a4514a88ea_arm64 as a component of Red Hat Container Native Virtualization 4.20
  • registry.redhat.io/container-native-virtualization/virt-exportproxy-rhel9@sha256:e37554e0deab3f352e85b07fb5f22f0eee229de28ff690072f82ca9aeae57e07_amd64 as a component of Red Hat Container Native Virtualization 4.20
  • registry.redhat.io/container-native-virtualization/virt-exportserver-rhel9@sha256:00f49bb2a1cd0110d8240ca63d2a2e54f03453c2496fce7115dd00013691ea99_amd64 as a component of Red Hat Container Native Virtualization 4.20
  • registry.redhat.io/container-native-virtualization/virt-exportserver-rhel9@sha256:354c24e67866c4ea5c90d3ed5b47e6a356e5df476c340650b99f08f8649e60ad_s390x as a component of Red Hat Container Native Virtualization 4.20
  • +13 more not shown

✅ Remediation

Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258 Workaround: The following measures reduce the attacker pool and limit secondary impact: Review RBAC policies to restrict pods/exec permissions on virt-launcher pods to only those users who strictly require it. This reduces the number of identities that can place symlinks in the launcher filesystem. Ensure SELinux is in enforcing mode (default in OpenShift). While SELinux does not prevent the notify socket hijacking path, it restricts the set of host files targetable through the chown/chmod path by blocking operations on files with protected security labels. RHCOS immutable filesystem layers prevent modification of core OS files through the chown/chmod path. Note: no mitigation currently addresses the notify socket hijacking vector. The attacker's ability to inject domain events into virt-handler is not constrained by SELinux or filesystem immutability. Workaround: Restrict pods/exec permissions in namespaces that run virtual machines. The pods/exec RBAC permission is required for the attack — removing it from VM operator roles prevents exploitation. Additionally, enable Kubernetes audit logging and monitor for kubectl exec commands targeting virt-launcher pods, especially during live migration events. Workaround: To mitigate this issue, implement infrastructure-level normalization to ensure all incoming HTTP/2 `:path` headers are properly formatted with a leading slash before reaching the gRPC-Go server. This can be achieved by configuring a reverse proxy or API gateway to validate and normalize the `:path` header. Ensure that any such intermediary is properly configured and restarted to apply the changes, which may temporarily impact service availability.

🔗 References (6)