RHSA-2026:53826HighCVSS 8.8

Red Hat Security Advisory: OpenShift Virtualization v4.15 Images

Published
August 11, 2026
Last Modified
August 17, 2026

🔗 CVE IDs covered (2)

📋 Description

CVE-2026-13201 — kubevirt: virt-handler-rhel9: kubevirt: safepath symlink following in virt-handler enables notify socket hijacking and node-level VM disruption CVE-2026-13622 — kubevirt: virt-handler-rhel9: kubevirt: virt-handler migration proxy follows symlinks allowing container escape to host

🎯 Affected products21

  • Red Hat Container Native Virtualization 4.15
  • registry.redhat.io/container-native-virtualization/libguestfs-tools-rhel9@sha256:aedd7f959b6071ea2ad10775d35c7724afbe354e98e97e9bbfb2269a2eaba336_amd64 as a component of Red Hat Container Native Virtualization 4.15
  • registry.redhat.io/container-native-virtualization/libguestfs-tools-rhel9@sha256:c503c6591376c5fcb5378ddc6cbedd595da8f1bc9d62582e170636f9a9274872_arm64 as a component of Red Hat Container Native Virtualization 4.15
  • registry.redhat.io/container-native-virtualization/pr-helper-rhel9@sha256:20baa60bac31b7d96525795c89031e9f35e02d1bbb31dd4d16e58755926ddb89_amd64 as a component of Red Hat Container Native Virtualization 4.15
  • registry.redhat.io/container-native-virtualization/pr-helper-rhel9@sha256:6391ba895b8baa234b22228e0b822143eebd50083ef11b4e8c703725c1a5f05c_arm64 as a component of Red Hat Container Native Virtualization 4.15
  • registry.redhat.io/container-native-virtualization/virt-api-rhel9@sha256:11acc9aff7ee4bb22b33c763f45f4631e0513120626e6e137e772285f3202529_arm64 as a component of Red Hat Container Native Virtualization 4.15
  • registry.redhat.io/container-native-virtualization/virt-api-rhel9@sha256:cf7b04acbb016a1b2c6dd07d84c8464341ec81eb70454751318f8c236a7e3437_amd64 as a component of Red Hat Container Native Virtualization 4.15
  • registry.redhat.io/container-native-virtualization/virt-artifacts-server-rhel9@sha256:23adf4cece6ef76f89fa300536336ccd9781e4e26e2183ca8d9785804cb951fd_amd64 as a component of Red Hat Container Native Virtualization 4.15
  • registry.redhat.io/container-native-virtualization/virt-artifacts-server-rhel9@sha256:ce813e4d84b22e9fe3e23c1054475967b2486548dc1b306aa49ad3de4fe9c2cd_arm64 as a component of Red Hat Container Native Virtualization 4.15
  • registry.redhat.io/container-native-virtualization/virt-controller-rhel9@sha256:265165dfa7eb9d7b555fe3f873ab6a3169cdb69e8686da2002a236e60c3c7b97_arm64 as a component of Red Hat Container Native Virtualization 4.15
  • registry.redhat.io/container-native-virtualization/virt-controller-rhel9@sha256:f9768dd6aa89b5795ada064588ae5ef3a059954260bc8ae65d7150db7149b3b4_amd64 as a component of Red Hat Container Native Virtualization 4.15
  • registry.redhat.io/container-native-virtualization/virt-exportproxy-rhel9@sha256:59528c91615269d075632f608963bbb1647d16a6d39336fd27c02f2c55092310_amd64 as a component of Red Hat Container Native Virtualization 4.15
  • registry.redhat.io/container-native-virtualization/virt-exportproxy-rhel9@sha256:ad2ee02fd5bed3b540bbc67472c612a81844de087278b8649be7c7a2412d6ac0_arm64 as a component of Red Hat Container Native Virtualization 4.15
  • registry.redhat.io/container-native-virtualization/virt-exportserver-rhel9@sha256:016a771739bfc19789b5f8309c319e695815924b2a15d609c41ae34f6ee882b6_amd64 as a component of Red Hat Container Native Virtualization 4.15
  • registry.redhat.io/container-native-virtualization/virt-exportserver-rhel9@sha256:2cb4b5ff754810f32c07ec1f7ffebc155f76b3f783203531ebdcc285f31f48d5_arm64 as a component of Red Hat Container Native Virtualization 4.15
  • registry.redhat.io/container-native-virtualization/virt-handler-rhel9@sha256:03ba527519d94afd60abad5462687281b43720e22e9743f7a25cc16ab3226a78_arm64 as a component of Red Hat Container Native Virtualization 4.15
  • registry.redhat.io/container-native-virtualization/virt-handler-rhel9@sha256:103b8f6e708805eb7a9459ed899dc3226b63dd1a12a32a080dfecd1e73b418f0_amd64 as a component of Red Hat Container Native Virtualization 4.15
  • registry.redhat.io/container-native-virtualization/virt-launcher-rhel9@sha256:9a22836a5385883fe942594a9af16bb93d40cd4e6d8937860d8f5de5ec414526_amd64 as a component of Red Hat Container Native Virtualization 4.15
  • registry.redhat.io/container-native-virtualization/virt-launcher-rhel9@sha256:df91e2ee09ac61a77c1e3ff5c1d6b37b490075bd29e65f7c32ddc02a60c771f3_arm64 as a component of Red Hat Container Native Virtualization 4.15
  • registry.redhat.io/container-native-virtualization/virt-operator-rhel9@sha256:a624dcaa8896dbbed098849d3fc050b2541e58ecefe870948e5d29fdd776b9cb_amd64 as a component of Red Hat Container Native Virtualization 4.15
  • registry.redhat.io/container-native-virtualization/virt-operator-rhel9@sha256:d7247dfde92022ce958eb6171c6dc6c49450aea5e3e983c89971530efaf917b0_arm64 as a component of Red Hat Container Native Virtualization 4.15

✅ Remediation

Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258 Workaround: The following measures reduce the attacker pool and limit secondary impact: Review RBAC policies to restrict pods/exec permissions on virt-launcher pods to only those users who strictly require it. This reduces the number of identities that can place symlinks in the launcher filesystem. Ensure SELinux is in enforcing mode (default in OpenShift). While SELinux does not prevent the notify socket hijacking path, it restricts the set of host files targetable through the chown/chmod path by blocking operations on files with protected security labels. RHCOS immutable filesystem layers prevent modification of core OS files through the chown/chmod path. Note: no mitigation currently addresses the notify socket hijacking vector. The attacker's ability to inject domain events into virt-handler is not constrained by SELinux or filesystem immutability. Workaround: Restrict pods/exec permissions in namespaces that run virtual machines. The pods/exec RBAC permission is required for the attack — removing it from VM operator roles prevents exploitation. Additionally, enable Kubernetes audit logging and monitor for kubectl exec commands targeting virt-launcher pods, especially during live migration events.

🔗 References (5)