Red Hat Product Security has come to the conclusion that this CVE is not needed.
No vendor fix or workaround currently provided.
OpenCVE Recommended Actions
- Set spec.configuration.migrations.disableTLS to false in the KubeVirt custom resource to enforce mutual TLS on migration proxy connections.
- Deploy Kubernetes NetworkPolicies that allow inbound traffic to virt-handler pods only from other virt-handler and virt-launcher pods, thereby limiting access to the plaintext listener.
- Configure host or cluster firewall rules to block traffic to the virt-handler pod ports from any sources not explicitly allowed by the NetworkPolicies.
Generated by OpenCVE AI on June 26, 2026 at 13:22 UTC.
Tracking
Sign in to view the affected projects.
No advisories yet.
Tue, 04 Aug 2026 12:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Virt-handler-rhel9: kubevirt: kubevirt: disabletls migration setting removes authentication, exposing unauthenticated virtqemud proxy on all interfaces | virt-handler-rhel9: kubevirt: kubevirt: DisableTLS migration setting removes authentication, exposing unauthenticated virtqemud proxy on all interfaces |
| Metrics |
ssvc
|
Tue, 04 Aug 2026 12:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A flaw was found in KubeVirt's migration proxy. When spec.configuration.migrations.disableTLS is set to true on the KubeVirt custom resource, the target virt-handler binds a plain TCP listener on all interfaces (0.0.0.0/::) on a random port with no authentication, peer allow-list, or handshake token. This listener proxies directly into the target virt-launcher's virtqemud control socket. An attacker with a running pod on the cluster network can connect to this listener and issue unfiltered libvirt RPC commands against another tenant's virtual machine, including reading VM memory and configuration, modifying VM state via QMP, or destroying the VM. The bind address is unconditionally 0.0.0.0 — configuring a dedicated migration network via migrations.network only changes the advertised migration IP, not the listener bind address, so the port remains reachable on the pod network even when a dedicated migration network is configured. The API documentation describes disableTLS as removing "the additional layer of live migration encryption" without disclosing that it also removes all mutual authentication. | Red Hat Product Security has come to the conclusion that this CVE is not needed. |
| CPEs | ||
| Vendors & Products |
Redhat container Native Virtualization
|
|
| References |
|
Mon, 29 Jun 2026 20:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Redhat openshift Virtualization
|
|
| Vendors & Products |
Redhat openshift Virtualization
|
Fri, 26 Jun 2026 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 26 Jun 2026 12:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
| |
| Metrics |
threat_severity
|
threat_severity
|
Fri, 26 Jun 2026 11:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A flaw was found in KubeVirt's migration proxy. When spec.configuration.migrations.disableTLS is set to true on the KubeVirt custom resource, the target virt-handler binds a plain TCP listener on all interfaces (0.0.0.0/::) on a random port with no authentication, peer allow-list, or handshake token. This listener proxies directly into the target virt-launcher's virtqemud control socket. An attacker with a running pod on the cluster network can connect to this listener and issue unfiltered libvirt RPC commands against another tenant's virtual machine, including reading VM memory and configuration, modifying VM state via QMP, or destroying the VM. The bind address is unconditionally 0.0.0.0 — configuring a dedicated migration network via migrations.network only changes the advertised migration IP, not the listener bind address, so the port remains reachable on the pod network even when a dedicated migration network is configured. The API documentation describes disableTLS as removing "the additional layer of live migration encryption" without disclosing that it also removes all mutual authentication. | |
| Title | Virt-handler-rhel9: kubevirt: kubevirt: disabletls migration setting removes authentication, exposing unauthenticated virtqemud proxy on all interfaces | |
| First Time appeared |
Redhat
Redhat container Native Virtualization |
|
| Weaknesses | CWE-306 | |
| CPEs | cpe:/a:redhat:container_native_virtualization:4 | |
| Vendors & Products |
Redhat
Redhat container Native Virtualization |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: REJECTED
Assigner: redhat
Published:
Updated: 2026-08-04T11:37:25.865Z
Reserved: 2026-06-25T10:28:26.197Z
Link: CVE-2026-13325
Updated:
Status : Rejected
Published: 2026-06-26T11:16:30.830
Modified: 2026-08-04T12:16:24.140
Link: CVE-2026-13325
OpenCVE Enrichment
Updated: 2026-06-29T19:45:02Z
-
CWE-306
Missing Authentication for Critical Function