Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-9m94-w2vq-hcf9 | KubeVirt VMI Denial-of-Service (DoS) Using Pod Impersonation |
Tue, 25 Nov 2025 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:kubevirt:kubevirt:*:*:*:*:*:kubernetes:*:* cpe:2.3:a:kubevirt:kubevirt:1.7.0:alpha0:*:*:*:kubernetes:*:* |
Wed, 12 Nov 2025 00:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
| |
| Metrics |
threat_severity
|
threat_severity
|
Mon, 10 Nov 2025 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 10 Nov 2025 09:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Kubevirt
Kubevirt kubevirt |
|
| Vendors & Products |
Kubevirt
Kubevirt kubevirt |
Fri, 07 Nov 2025 23:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | KubeVirt is a virtual machine management add-on for Kubernetes. Prior to 1.7.0-beta.0, a logic flaw in the virt-controller allows an attacker to disrupt the control over a running VMI by creating a pod with the same labels as the legitimate virt-launcher pod associated with the VMI. This can mislead the virt-controller into associating the fake pod with the VMI, resulting in incorrect status updates and potentially causing a DoS (Denial-of-Service). This vulnerability is fixed in 1.7.0-beta.0. | |
| Title | KubeVirt VMI Denial-of-Service (DoS) Using Pod Impersonation | |
| Weaknesses | CWE-703 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2025-11-10T19:01:13.977Z
Reserved: 2025-11-03T22:12:51.365Z
Link: CVE-2025-64435
Updated: 2025-11-10T19:00:55.699Z
Status : Analyzed
Published: 2025-11-07T23:15:45.850
Modified: 2025-11-25T17:15:44.140
Link: CVE-2025-64435
OpenCVE Enrichment
Updated: 2025-11-10T09:33:52Z
Github GHSA