GPU VulnDB

Database/Container, Kubernetes & orchestration

KubeVirt: virt-handler service-account permissions (update VMI, patch nodes) can be abused to force VMI migration

CVE-2025-64436Container, Kubernetes & orchestrationcurated

Impact

virt-handler service-account permissions (update VMI, patch nodes) can be abused to force VMI migration

Who can reach it

An attacker with virt-handler credentials

What to do

Upgrade KubeVirt; scope down the service account

References

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.