CVE-2025-64324

Aliases:GHSA-46xp-26xh-hpqhGO-2025-4110CGA-82qm-xw3m-w7v7CGA-fp7q-339r-6869CGA-3hmf-fqcf-3x72CGA-4jg5-m83f-6m3hCGA-5vjw-8pxh-8rmcCGA-6j4v-4vq2-53j7CGA-77hv-qc76-cp86CGA-7qvf-8rc9-mpmjCGA-8f33-cg8g-wf89CGA-8mm8-r2v8-h62fCGA-92xw-4m7f-859hCGA-c3cp-h7rg-wchpCGA-c6mq-xjg6-5gvvCGA-fcxg-393w-g878CGA-fwcj-m4fw-g6fhCGA-grfr-h6vw-v9xxCGA-h459-xcr5-97rhCGA-j7gf-5rrj-h4x7CGA-j8gj-2vrp-7w55CGA-m74p-3v8x-6f5hCGA-mm77-mg8m-jmxjCGA-p3rf-hrw2-r2h7CGA-qp78-v43f-6qw9CGA-qp87-m6xg-598wCGA-qwh7-w9cj-f8w5CGA-v6w3-4232-rpjhCGA-v7xm-g7c3-8fqjCGA-w39m-2hvj-9gp4CGA-w7qg-xpjp-p8chCGA-wgv3-gv6w-cwhrCGA-xv7m-8qpr-x5fpCGA-xwq5-jgc2-w6h3
Analyzed
Published: 18 Nov 2025, 22:10
Last modified:26 Feb 2026, 16:21

Vulnerability Summary

Overall Risk (default)
medium
44/100
CVSS Score
8.5 HIGH
v4.0 (cve.org)
EPSS Score
0.22% LOW
0% probability +0.21%
KEV
Not listed
Ransomware
No reports
Public exploits
1 found
Dark Web
Not detected

Timeline

18 Nov 2025, 22:10
Published
Vulnerability first disclosed
26 Feb 2026, 16:21
Last Modified
Vulnerability information updated

Description

KubeVirt is a virtual machine management add-on for Kubernetes. The `hostDisk` feature in KubeVirt allows mounting a host file or directory owned by the user with UID 107 into a VM. However, prior to version 1.6.1 and 1.7.0, the implementation of this feature and more specifically the `DiskOrCreate` option (which creates a file if it doesn't exist) has a logic bug that allows an attacker to read and write arbitrary files owned by more privileged users on the host system. Versions 1.6.1 and 1.7.0 fix the issue.

CVSS Metrics

  • v4.0HIGHScore: 8.5CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
  • v4.0HIGHScore: 8.5CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  • v3.1HIGHScore: 7.7CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

EPSS Trends

Current EPSS score: 0.22% Percentile: 13%

Techniques & Countermeasures

  • CWE-200Exposure of Sensitive Information to an Unauthorized Actor

    The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

  • CWE-732Incorrect Permission Assignment for Critical Resource

    The product specifies permissions for a security-critical resource in a way that allows that resource to be read or modified by unintended actors.

Affected Systems

  • chainguarddocker-machine-driver-harvester

    < 1.0.6-r4

  • chainguardvirt-api-1.6

    < 1.6.4-r0

  • chainguardvirt-api-fips-1.6

    < 1.6.4-r0

  • chainguardvirt-chroot-1.6

    < 1.6.4-r0

  • chainguardvirt-chroot-fips-1.6

    < 1.6.4-r0

  • chainguardvirt-controller-1.6

    < 1.6.4-r0

  • chainguardvirt-controller-fips-1.6

    < 1.6.4-r0

  • chainguardvirt-handler-1.6

    < 1.6.4-r0

  • chainguardvirt-handler-fips-1.6

    < 1.6.4-r0

  • chainguardvirt-launcher-1.6

    < 1.6.6-r3

  • chainguardvirt-launcher-1.6-virt-freezer

    < 1.6.6-r3

  • chainguardvirt-launcher-1.6-virt-launcher-monitor

    < 1.6.6-r3

  • chainguardvirt-launcher-1.6-virt-probe

    < 1.6.6-r3

  • chainguardvirt-launcher-1.6-virt-tail

    < 1.6.6-r3

  • chainguardvirt-operator-1.6

    < 1.6.6-r1

  • chainguardvirt-operator-fips-1.6

    < 1.6.6-r2

  • wolfidocker-machine-driver-harvester

    < 1.0.6-r4

  • kubevirt.iokubevirt

    ≥ 1.6.2, < 1.7.0-rc.0 | < 1.6.1 | ≥ 1.7.0-alpha.0, < 1.7.0-rc.0

  • kubevirtkubevirt

    ≥ 1.7.0-alpha.0, < 1.7.0-rc.0 | < 1.6.1 | 1.7.0:alpha0 | 1.7.0:beta0

References (7)