๐Ÿ” CVE Alert

CVE-2025-64324

UNKNOWN 0.0

KubeVirt Vulnerable to Arbitrary Host File Read and Write

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

KubeVirt is a virtual machine management add-on for Kubernetes. The `hostDisk` feature in KubeVirt allows mounting a host file or directory owned by the user with UID 107 into a VM. However, prior to version 1.6.1 and 1.7.0, the implementation of this feature and more specifically the `DiskOrCreate` option (which creates a file if it doesn't exist) has a logic bug that allows an attacker to read and write arbitrary files owned by more privileged users on the host system. Versions 1.6.1 and 1.7.0 fix the issue.

CWE CWE-200 CWE-732
Vendor kubevirt
Product kubevirt
Published Nov 18, 2025
Last Updated Feb 26, 2026
Stay Ahead of the Next One

Get instant alerts for kubevirt kubevirt

Be the first to know when new unknown vulnerabilities affecting kubevirt kubevirt are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

kubevirt / kubevirt
0 < 1.6.1 1.7.0-alpha.0 < 1.7.0-rc.0

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/kubevirt/kubevirt/security/advisories/GHSA-46xp-26xh-hpqh github.com: https://github.com/kubevirt/kubevirt/pull/15037 github.com: https://github.com/kubevirt/kubevirt/commit/00d03e43e3bf03e563136695a4732b65ed42d764 github.com: https://github.com/kubevirt/kubevirt/commit/ff3b69b08b6b9c8d08d23735ca8d82455f790a69