CVE-2026-7374: Red Hat Container Native Virtualization 4.12

Critical severity, CVSS 9.9. EPSS: 0.8% chance of exploitation in the next 30 days.

A flaw was found in KubeVirt's virt-handler component. This vulnerability allows an authenticated OpenShift user with edit permissions in a single namespace to exploit improper symlink validation when connecting to virtual machine console sockets. By replacing the console socket with a symlink to the host's container runtime (CRI-O) socket, an attacker can hijack virt-handler's privileged connection. This enables the attacker to access any Unix socket on the host, potentially leading to full control of the node and the entire cluster.

Affected products

  • Red Hat Red Hat Container Native Virtualization 4.12: before 1779375376 (fixed in 1779375376)
  • Red Hat Red Hat Container Native Virtualization 4.13: before 1778999881 (fixed in 1778999881)
  • Red Hat Red Hat Container Native Virtualization 4.14: before 1779321599 (fixed in 1779321599)
  • Red Hat Red Hat Container Native Virtualization 4.15: before 1778859977 (fixed in 1778859977)
  • Red Hat Red Hat Container Native Virtualization 4.16: before 1778861274 (fixed in 1778861274)
  • Red Hat Red Hat Container Native Virtualization 4.17: before 1779174925 (fixed in 1779174925)
  • Red Hat Red Hat Container Native Virtualization 4.18: before 1778887155 (fixed in 1778887155)
  • Red Hat Red Hat Container Native Virtualization 4.19: before 1779289071 (fixed in 1779289071)
  • Red Hat Red Hat Container Native Virtualization 4.20: before 1779288737 (fixed in 1779288737)
  • Red Hat Red Hat Container Native Virtualization 4.21: before 1779420069 (fixed in 1779420069)

Published 2026-05-26. Last modified 2026-09-10.