Critical severity9.9NVD Advisory· Published May 26, 2026· Updated Aug 24, 2026
CVE-2026-7374
CVE-2026-7374
Description
A flaw was found in KubeVirt's virt-handler component. This vulnerability allows an authenticated OpenShift user with edit permissions in a single namespace to exploit improper symlink validation when connecting to virtual machine console sockets. By replacing the console socket with a symlink to the host's container runtime (CRI-O) socket, an attacker can hijack virt-handler's privileged connection. This enables the attacker to access any Unix socket on the host, potentially leading to full control of the node and the entire cluster.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
kubevirt.io/kubevirtGo | >= 1.8.0-alpha.0, < 1.8.3 | 1.8.3 |
kubevirt.io/kubevirtGo | >= 1.7.0-alpha.0, < 1.7.4 | 1.7.4 |
kubevirt.io/kubevirtGo | < 1.6.6 | 1.6.6 |
Affected products
13- osv-coords11 versionspkg:apk/chainguard/docker-machine-driver-harvesterpkg:apk/chainguard/harvesterpkg:apk/chainguard/harvester-fipspkg:apk/chainguard/harvester-fips-upgrade-helperpkg:apk/chainguard/harvester-fips-webhookpkg:apk/chainguard/harvester-upgrade-helperpkg:apk/chainguard/harvester-webhookpkg:apk/wolfi/docker-machine-driver-harvesterpkg:rpm/opensuse/govulncheck-vulndb&distro=openSUSE%20Leap%2016.0pkg:rpm/suse/kubevirt&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Containers%2015%20SP7pkg:rpm/suse/kubevirt-1.6&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Containers%2015%20SP7
< 1.0.6-r13+ 10 more
- (no CPE)range: < 1.0.6-r13
- (no CPE)range: < 1.8.1-r1
- (no CPE)range: < 1.8.1-r1
- (no CPE)range: < 1.8.1-r1
- (no CPE)range: < 1.8.1-r1
- (no CPE)range: < 1.8.1-r1
- (no CPE)range: < 1.8.1-r1
- (no CPE)range: < 1.0.6-r13
- (no CPE)range: < 0.0.20260723T184607-160000.1.1
- (no CPE)range: < 1.7.4-150700.3.24.2
- (no CPE)range: < 1.6.6-150700.15.7.1
Patches
Vulnerability mechanics
References
17- github.com/advisories/GHSA-7jcp-v9w4-wjmgghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2026-7374ghsaADVISORY
- access.redhat.com/errata/RHSA-2026:20720nvdWEB
- access.redhat.com/errata/RHSA-2026:20736nvdWEB
- access.redhat.com/errata/RHSA-2026:20763nvdWEB
- access.redhat.com/errata/RHSA-2026:20767nvdWEB
- access.redhat.com/errata/RHSA-2026:20782nvdWEB
- access.redhat.com/errata/RHSA-2026:20825nvdWEB
- access.redhat.com/errata/RHSA-2026:20866nvdWEB
- access.redhat.com/errata/RHSA-2026:20886nvdWEB
- access.redhat.com/errata/RHSA-2026:20890nvdWEB
- access.redhat.com/errata/RHSA-2026:20975nvdWEB
- access.redhat.com/security/cve/CVE-2026-7374nvdWEB
- bugzilla.redhat.com/show_bug.cginvdWEB
- github.com/kubevirt/kubevirt/commit/011eef8129e2c21e0ea496f283ee1676009bc757ghsaWEB
- github.com/kubevirt/kubevirt/pull/17916ghsaWEB
- security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-7374.jsonnvdWEB
News mentions
0No linked articles in our index yet.