CVE-2026-102623: Red Hat Openshift Virtualization 4

Medium severity, CVSS 6.5. EPSS: 0.3% chance of exploitation in the next 30 days.

A flaw was found in KubeVirt. An authenticated user with permission to create Virtual Machine Instances (VMIs) can cause a Denial of Service (DoS) by submitting a virtual machine definition with an empty ephemeral volume. The virt-controller component fails to properly validate the volume configuration, leading to an unhandled exception and application crash during processing. Because the malformed definition persists in the cluster, the controller enters a continuous crash loop, disrupting virtual machine lifecycle operations across the entire environment.

Affected products

  • Red Hat Red Hat Openshift Virtualization 4

Published 2026-09-29. Last modified 2026-09-29.