Database/Container, Kubernetes & orchestration
KubeVirt: Improper symlink validation in virt-handler lets a user with edit rights in one namespace escape to the host
CVE-2026-7374Container, Kubernetes & orchestrationcurated
Impact
Improper symlink validation in virt-handler lets a user with edit rights in one namespace escape to the host; the most severe KubeVirt issue
Who can reach it
Cluster user with namespace access
What to do
Emergency KubeVirt upgrade; virt-handler DaemonSet rollout on every node
References
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.