THREAT OPS › Threat News › [NVD] CVE-2026-13622 (HIGH 8.8) — A symlink following vulnerability was found in KubeVirt's virt-handler migration proxy. During live migration, virt-handler dials Unix sockets inside the target virt-launcher pod via /proc/<pid>/root/ paths using net.Dial() without symlink protection. These socket paths reside in
[NVD] CVE-2026-13622 (HIGH 8.8) — A symlink following vulnerability was found in KubeVirt's virt-handler migration proxy. During live migration, virt-handler dials Unix sockets inside the target virt-launcher pod via /proc/<pid>/root/ paths using net.Dial() without symlink protection. These socket paths reside in
CVE-2026-13622 CVSS: 8.8 HIGH Published: 2026-08-12T21:17:35.630
A symlink following vulnerability was found in KubeVirt's virt-handler migration proxy. During live migration, virt-handler dials Unix sockets inside the target virt-launcher pod via /proc/<pid>/root/ paths using net.Dial() without symlink protection. These socket paths reside in qemu-owned directories writable by the virt-launcher
Indicators of compromise
- CVE-2026-13622cve
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-13622