← All Advisories

CVE-2026-13622

Last refreshed2026-10-03

Status: UPDATED  |  Advisory ID: CVE-2026-13622

Key Details

CVECVE-2026-13622
CVSS Score / Version8.8 (High) / CVSS v3.1
Updated2026-09-21
CVSS VectorCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
CVSS Proseattack vector is local; attack complexity is low; privileges required is low; user interaction is none; scope is changed; confidentiality impact is high; integrity impact is high; availability impact is high.
Affected productssee table below
Classified asCWE-22 (Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal'))

Affected Products, Subsystems & Sectors

VendorProductAffected VersionsPatch Status
Red HatRed Hat Container Native Virtualization 4.13
Red HatRed Hat Container Native Virtualization 4.14
Red HatRed Hat Container Native Virtualization 4.15
Red HatRed Hat Container Native Virtualization 4.16
Red HatRed Hat Container Native Virtualization 4.17
Red HatRed Hat Container Native Virtualization 4.18
Red HatRed Hat Container Native Virtualization 4.19
Red HatRed Hat Container Native Virtualization 4.20
Red HatRed Hat Container Native Virtualization 4.21
Red HatRed Hat Container Native Virtualization 4.22
Red HatRed Hat Container Native Virtualization 4.12
SubsystemsGeneral OT
SectorsMultiple

What to Know

A symlink following vulnerability was found in KubeVirt's virt-handler migration proxy. During live migration, virt-handler dials Unix sockets inside the target virt-launcher pod via /proc/<pid>/root/ paths using net.Dial() without symlink protection. These socket paths reside in qemu-owned directories writable by the virt-launcher user. An attacker with namespace edit and pods/exec permissions can replace a migration proxy socket with a symlink to the host CRI-O socket. Because virt-handler runs as root in the host mount namespace, absolute symlink targets resolve against the host filesystem, and the bidirectional io.Copy proxy relays attacker-controlled bytes to the container runtime, enabling full node compromise. (NVD)

What to Do

Monitor Red Hat's web page for any future patch releases.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-13622
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-13622