CVE detail
CVE-2026-13622
A symlink following vulnerability was found in KubeVirt's virt-handler migration proxy. During live migration, virt-handler dials Unix sockets inside the target virt-launcher pod via /proc/<pid>/root/ paths using net.Dial() without symlink protection. These socket paths reside in qemu-owned directories writable by the virt-launcher user. An attacker with namespace edit and pods/exec permissions can replace a migration proxy socket with a symlink to the host CRI-O socket. Because virt-handler runs as root in the host mount namespace, absolute symlink targets resolve against the host filesystem, and the bidirectional io.Copy proxy relays attacker-controlled bytes to the container runtime, enabling full node compromise.
Buzz score
Why this CVE is surfacing
This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.
Buzz score components · mention 26.4 · diversity 6.5 · KEV 0.0 · OTX 0.0 · PoC 0.0
Why it matters now
Mention timeline
- Total mentions
- 13
- within the 30d window
- Peak daily
- 13
- highest bucket
Evidence
Source links by recency
13 source links · newest first
- https://access.redhat.com/errata/RHSA-2026:53826access.redhat.com
No excerpt available.
Exploitaccess.redhat.comAug 12, 2026, 9:17 PM - https://access.redhat.com/errata/RHSA-2026:53797access.redhat.com
No excerpt available.
Exploitaccess.redhat.comAug 12, 2026, 9:17 PM - https://access.redhat.com/errata/RHSA-2026:53728access.redhat.com
No excerpt available.
Exploitaccess.redhat.comAug 12, 2026, 9:17 PM - https://access.redhat.com/errata/RHSA-2026:53721access.redhat.com
No excerpt available.
Exploitaccess.redhat.comAug 12, 2026, 9:17 PM - https://access.redhat.com/errata/RHEA-2026:53670access.redhat.com
No excerpt available.
Exploitaccess.redhat.comAug 12, 2026, 9:17 PM - https://access.redhat.com/errata/RHSA-2026:53838access.redhat.com
No excerpt available.
Exploitaccess.redhat.comAug 12, 2026, 9:17 PM - https://access.redhat.com/errata/RHSA-2026:53763access.redhat.com
No excerpt available.
Exploitaccess.redhat.comAug 12, 2026, 9:17 PM - https://access.redhat.com/errata/RHSA-2026:53684access.redhat.com
No excerpt available.
Exploitaccess.redhat.comAug 12, 2026, 9:17 PM - https://access.redhat.com/errata/RHSA-2026:53671access.redhat.com
No excerpt available.
Exploitaccess.redhat.comAug 12, 2026, 9:17 PM - https://access.redhat.com/errata/RHSA-2026:53655access.redhat.com
No excerpt available.
Exploitaccess.redhat.comAug 12, 2026, 9:17 PM - https://access.redhat.com/errata/RHSA-2026:51031access.redhat.com
No excerpt available.
Exploitaccess.redhat.comAug 12, 2026, 9:17 PM - https://bugzilla.redhat.com/show_bug.cgi?id=2494142bugzilla.redhat.com
No excerpt available.
Exploitbugzilla.redhat.comAug 12, 2026, 9:17 PM - https://access.redhat.com/security/cve/CVE-2026-13622access.redhat.com
No excerpt available.
Exploitaccess.redhat.comAug 12, 2026, 9:17 PM
Exploit code
Public exploit repository references
Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.
0 repository references · best confidence N/A · max 0 stars
Related records
Similar CVEs
6 related CVEs with shared weakness or product evidence
- CVE-2026-18554CVSS 7.5 · High
IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote authenticated attacker to obtain sensitive information due to improper limitation of a pathname to a restricted directo…
- CVE-2026-18178CVSS 5.4 · Medium
IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote authenticated attacker to delete arbitrary files due to path traversal.
- CVE-2026-17181CVSS 9.3 · Critical
IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker to write files to arbitrary locations due to path traversal.
- CVE-2026-17173CVSS 6.5 · Medium
IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote authenticated attacker to obtain sensitive information due to improper validation of file paths.
- CVE-2026-17081CVSS 8.2 · High
IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker to write arbitrary files due to improper limitation of a pathname to a restricted directory.
- CVE-2026-16915CVSS 7.5 · High
IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote authenticated attacker to obtain sensitive information due to improper input validation.