Import Source
https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-91463.json
JSON Data
https://api.osv.dev/v1/vulns/AZL-91463
Upstream
  • CVE-2026-13218
Published
2026-06-26T00:16:51Z
Modified
2026-08-29T05:27:27Z
Summary
CVE-2026-13218 affecting package kubevirt 1.7.1-8
Details

A flaw was found in KubeVirt's virt-handler network cache handling. The WriteToCachedFile function writes data to a launcher-rooted path using os.WriteFile and os.Chown without symlink protection. A user with access to the virt-launcher container can plant a symlink at the cache file path, causing virt-handler to follow it and overwrite an arbitrary host file with JSON content and change its ownership.

References

Affected packages

Azure Linux:3 / kubevirt

Package

Name
kubevirt
Purl
pkg:rpm/azure-linux/kubevirt

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Last affected
1.7.1-8

Database specific

source
"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-91463.json"