RHSA-2026:53797HighCVSS 8.8

Red Hat Security Advisory: OpenShift Virtualization v4.19 Images

Published
August 11, 2026
Last Modified
August 14, 2026

🔗 CVE IDs covered (2)

📋 Description

CVE-2026-13201 — kubevirt: virt-handler-rhel9: kubevirt: safepath symlink following in virt-handler enables notify socket hijacking and node-level VM disruption CVE-2026-13622 — kubevirt: virt-handler-rhel9: kubevirt: virt-handler migration proxy follows symlinks allowing container escape to host

🎯 Affected products40

  • Red Hat Container Native Virtualization 4.19
  • registry.redhat.io/container-native-virtualization/libguestfs-tools-rhel9@sha256:20074559bf1e16642be941f7120c60b51baf8ac16a5915a43d8bc2cf52ef869e_arm64 as a component of Red Hat Container Native Virtualization 4.19
  • registry.redhat.io/container-native-virtualization/libguestfs-tools-rhel9@sha256:631072d5e24ce9b403a23049886853af7cc681e62d279a29e5fbef2a152d2983_amd64 as a component of Red Hat Container Native Virtualization 4.19
  • registry.redhat.io/container-native-virtualization/libguestfs-tools-rhel9@sha256:bb026cb6cee4edb17ce9c938726ddbba5be26e86f9a3fd0fbad6ced223bc1ef4_s390x as a component of Red Hat Container Native Virtualization 4.19
  • registry.redhat.io/container-native-virtualization/passt-network-binding-plugin-cni-rhel9@sha256:76c9d8365a7136ef18185c83f7e1a11e9dad74feae64047962abd5ad0bf68f52_amd64 as a component of Red Hat Container Native Virtualization 4.19
  • registry.redhat.io/container-native-virtualization/passt-network-binding-plugin-cni-rhel9@sha256:8c5cbe3a0e1e8284d04872eb35563a6ef39c585d4e3f0cb982f167e4e33eaa4a_s390x as a component of Red Hat Container Native Virtualization 4.19
  • registry.redhat.io/container-native-virtualization/passt-network-binding-plugin-cni-rhel9@sha256:e7a68b2ab5cdbf9a99b8c81751ba66091ceea01923f7d846652a837d74f935f5_arm64 as a component of Red Hat Container Native Virtualization 4.19
  • registry.redhat.io/container-native-virtualization/passt-network-binding-plugin-sidecar-rhel9@sha256:40ce590c4aed26c5cb98b84ba4c13b939ec502dd622bcc8385162d1682de0e4f_s390x as a component of Red Hat Container Native Virtualization 4.19
  • registry.redhat.io/container-native-virtualization/passt-network-binding-plugin-sidecar-rhel9@sha256:47397b4c466a57d17c881e35fe7b235b1091a0bf96b6468ec21a79c33110ffdd_arm64 as a component of Red Hat Container Native Virtualization 4.19
  • registry.redhat.io/container-native-virtualization/passt-network-binding-plugin-sidecar-rhel9@sha256:e10aca2e4f9c3c9b9147edf17dac229e0432f4741c467d952ea4956f020759d6_amd64 as a component of Red Hat Container Native Virtualization 4.19
  • registry.redhat.io/container-native-virtualization/pr-helper-rhel9@sha256:5f90cda5d1cfe419bfb25dd50d4b431bad27757657132de4fbd95d208ab228c4_amd64 as a component of Red Hat Container Native Virtualization 4.19
  • registry.redhat.io/container-native-virtualization/pr-helper-rhel9@sha256:864861b64ef685acd2202a783422c84d8a5e0a425ba4cc76b66c65c6c467ffcb_s390x as a component of Red Hat Container Native Virtualization 4.19
  • registry.redhat.io/container-native-virtualization/pr-helper-rhel9@sha256:c53e87ebb684102daa6e86a8f01d369d02a0d82b571a8c26bcc3eff69bb1b176_arm64 as a component of Red Hat Container Native Virtualization 4.19
  • registry.redhat.io/container-native-virtualization/sidecar-shim-rhel9@sha256:c97962123875fff46b0e8ac48fc5dd44dbe84eb82ba5c3f9ced3184b03a7aa99_arm64 as a component of Red Hat Container Native Virtualization 4.19
  • registry.redhat.io/container-native-virtualization/sidecar-shim-rhel9@sha256:ef7a01f58b00b4ecb0e18c81fd08e4e6d39991f3f35fcfdd39e78bac19a230b7_s390x as a component of Red Hat Container Native Virtualization 4.19
  • registry.redhat.io/container-native-virtualization/sidecar-shim-rhel9@sha256:f79d6aee0797056d7902ff01beb74f2886c60ed30ac36ca874627ef92c93b98e_amd64 as a component of Red Hat Container Native Virtualization 4.19
  • registry.redhat.io/container-native-virtualization/virt-api-rhel9@sha256:310c8ab06c81c231aa7e512a7356a2e479b8a3b2247fea0c843c376152000dc7_amd64 as a component of Red Hat Container Native Virtualization 4.19
  • registry.redhat.io/container-native-virtualization/virt-api-rhel9@sha256:38e60dba51bd59739454978f7a236a80978ec52f13903e3a0458d31a05b3b742_s390x as a component of Red Hat Container Native Virtualization 4.19
  • registry.redhat.io/container-native-virtualization/virt-api-rhel9@sha256:4d5b5765c06553147d7024c90620a23e7e6bc1822cc676ee006984827ab1d39a_arm64 as a component of Red Hat Container Native Virtualization 4.19
  • registry.redhat.io/container-native-virtualization/virt-artifacts-server-rhel9@sha256:8648240ee58a62a7c0d00857af7edfbca9fe9562e3b1550cea3a4692accc5a43_arm64 as a component of Red Hat Container Native Virtualization 4.19
  • registry.redhat.io/container-native-virtualization/virt-artifacts-server-rhel9@sha256:ac6b8f4269ee9160d3d1420512b5dabd6d83fcf04c7a03633da2aa2fa02a1b1f_amd64 as a component of Red Hat Container Native Virtualization 4.19
  • registry.redhat.io/container-native-virtualization/virt-artifacts-server-rhel9@sha256:eb438192ce86fccb647a437b78bc062afb2b1db4fa795f1cf7eed10c53d80518_s390x as a component of Red Hat Container Native Virtualization 4.19
  • registry.redhat.io/container-native-virtualization/virt-controller-rhel9@sha256:34cf237bdeed207aac7ad2aa4be2ac56ed3788fc219bb0b96782dab63e2ef5c0_s390x as a component of Red Hat Container Native Virtualization 4.19
  • registry.redhat.io/container-native-virtualization/virt-controller-rhel9@sha256:4443a5f3adb7748ae947e52ac6057eda21da523aa30c7ea98c9e597d2dcfacb9_arm64 as a component of Red Hat Container Native Virtualization 4.19
  • registry.redhat.io/container-native-virtualization/virt-controller-rhel9@sha256:fefdffe6668f239d93ca8b6f17fba5e588538633fbae80dc340d5043323b2b04_amd64 as a component of Red Hat Container Native Virtualization 4.19
  • registry.redhat.io/container-native-virtualization/virt-exportproxy-rhel9@sha256:37ece2effa3006649f104cbfe57a7f090c5949d379b6068e0c524b9c22519163_arm64 as a component of Red Hat Container Native Virtualization 4.19
  • registry.redhat.io/container-native-virtualization/virt-exportproxy-rhel9@sha256:88f5eabf7eec4254d393d2608e1f731a0acdd0f6ebba66734fe35da40c5bec1d_amd64 as a component of Red Hat Container Native Virtualization 4.19
  • registry.redhat.io/container-native-virtualization/virt-exportproxy-rhel9@sha256:e229e5c04cd98eec9a7753406856569acffe406d02905c1c2ae3c97e1ce44e9b_s390x as a component of Red Hat Container Native Virtualization 4.19
  • registry.redhat.io/container-native-virtualization/virt-exportserver-rhel9@sha256:2caa98a2f2e2a6f21a53996a49700cf8560a6ab9ec6e829bf6d61b37c59051a6_s390x as a component of Red Hat Container Native Virtualization 4.19
  • registry.redhat.io/container-native-virtualization/virt-exportserver-rhel9@sha256:97dd127afcf6af9f5c26a99fe382ba23a3c6ec7b4b3ed165662ca520b022c5ca_arm64 as a component of Red Hat Container Native Virtualization 4.19
  • +10 more not shown

✅ Remediation

Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258 Workaround: The following measures reduce the attacker pool and limit secondary impact: Review RBAC policies to restrict pods/exec permissions on virt-launcher pods to only those users who strictly require it. This reduces the number of identities that can place symlinks in the launcher filesystem. Ensure SELinux is in enforcing mode (default in OpenShift). While SELinux does not prevent the notify socket hijacking path, it restricts the set of host files targetable through the chown/chmod path by blocking operations on files with protected security labels. RHCOS immutable filesystem layers prevent modification of core OS files through the chown/chmod path. Note: no mitigation currently addresses the notify socket hijacking vector. The attacker's ability to inject domain events into virt-handler is not constrained by SELinux or filesystem immutability. Workaround: Restrict pods/exec permissions in namespaces that run virtual machines. The pods/exec RBAC permission is required for the attack — removing it from VM operator roles prevents exploitation. Additionally, enable Kubernetes audit logging and monitor for kubectl exec commands targeting virt-launcher pods, especially during live migration events.

🔗 References (5)