Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-7xgm-5prm-v5gc | KubeVirt Excessive Role Permissions Could Enable Unauthorized VMI Migrations Between Nodes |
Tue, 25 Nov 2025 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:kubevirt:kubevirt:*:*:*:*:*:kubernetes:*:* | |
| Metrics |
cvssV3_1
|
cvssV3_1
|
Wed, 12 Nov 2025 00:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
| |
| Metrics |
threat_severity
|
cvssV3_1
|
Mon, 10 Nov 2025 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 10 Nov 2025 09:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Kubevirt
Kubevirt kubevirt |
|
| Vendors & Products |
Kubevirt
Kubevirt kubevirt |
Fri, 07 Nov 2025 23:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | KubeVirt is a virtual machine management add-on for Kubernetes. In 1.5.0 and earlier, the permissions granted to the virt-handler service account, such as the ability to update VMI and patch nodes, could be abused to force a VMI migration to an attacker-controlled node. This vulnerability could otherwise allow an attacker to mark all nodes as unschedulable, potentially forcing the migration or creation of privileged pods onto a compromised node. | |
| Title | KubeVirt Excessive Role Permissions Could Enable Unauthorized VMI Migrations Between Nodes | |
| Weaknesses | CWE-269 CWE-276 |
|
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2025-11-10T18:53:09.436Z
Reserved: 2025-11-03T22:12:51.365Z
Link: CVE-2025-64436
Updated: 2025-11-10T18:52:58.382Z
Status : Analyzed
Published: 2025-11-07T23:15:46.003
Modified: 2025-11-25T17:17:28.350
Link: CVE-2025-64436
OpenCVE Enrichment
Updated: 2025-11-10T09:33:50Z
Github GHSA