Import Source
https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-69790.json
JSON Data
https://api.osv.dev/v1/vulns/AZL-69790
Upstream
Published
2025-11-07T23:15:46Z
Modified
2026-04-21T04:36:14.518077Z
Summary
CVE-2025-64436 affecting package kubevirt for versions less than 1.6.3-1
Details

KubeVirt is a virtual machine management add-on for Kubernetes. In 1.5.0 and earlier, the permissions granted to the virt-handler service account, such as the ability to update VMI and patch nodes, could be abused to force a VMI migration to an attacker-controlled node. This vulnerability could otherwise allow an attacker to mark all nodes as unschedulable, potentially forcing the migration or creation of privileged pods onto a compromised node.

References

Affected packages

Azure Linux:3 / kubevirt

Package

Name
kubevirt
Purl
pkg:rpm/azure-linux/kubevirt

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.6.3-1

Database specific

source
"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-69790.json"