GHSA-25mh-hp8x-cgrv

Suggest an improvement
Source
https://github.com/advisories/GHSA-25mh-hp8x-cgrv
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/01/GHSA-25mh-hp8x-cgrv/GHSA-25mh-hp8x-cgrv.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-25mh-hp8x-cgrv
Aliases
Downstream
Published
2026-01-26T21:30:36Z
Modified
2026-09-10T03:49:54Z
Severity
  • 6.4 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:L/A:L CVSS Calculator
Summary
KubeVirt Guest Agent DoS via Excessive Network Interface Reports
Details

A flaw was found in KubeVirt. A user within a virtual machine (VM), if the guest agent is active, can exploit this by causing the agent to report an excessive number of network interfaces. This action can overwhelm the system's ability to store VM configuration updates, effectively blocking changes to the Virtual Machine Instance (VMI). This allows the VM user to restrict the VM administrator's ability to manage the VM, leading to a Denial of Dervice for administrative operations.

Database specific
{
    "cwe_ids": [
        "CWE-770"
    ],
    "github_reviewed": true,
    "github_reviewed_at": "2026-01-27T21:29:13Z",
    "nvd_published_at": "2026-01-26T20:16:08Z",
    "severity": "MODERATE"
}
References

Affected packages

Go / kubevirt.io/kubevirt

Package

Name
kubevirt.io/kubevirt
View open source insights on deps.dev
Purl
pkg:golang/kubevirt.io/kubevirt

Affected ranges

Type
SEMVER
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Last Affected
1.7.0

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/01/GHSA-25mh-hp8x-cgrv/GHSA-25mh-hp8x-cgrv.json"