CVE-2025-64324

Aliases:GHSA-46xp-26xh-hpqhGO-2025-4110
Analyzed
Published: 18 Nov 2025, 22:10
Last modified:26 Feb 2026, 16:21

Vulnerability Summary

Overall Risk (default)
medium
44/100
CVSS Score
8.5 HIGH
v4.0 (cve.org)
EPSS Score
0.21% LOW
0% probability +0.20%
KEV
Not listed
Ransomware
No reports
Public exploits
1 found
Dark Web
Not detected

Timeline

18 Nov 2025, 22:10
Published
Vulnerability first disclosed
26 Feb 2026, 16:21
Last Modified
Vulnerability information updated

Description

KubeVirt is a virtual machine management add-on for Kubernetes. The `hostDisk` feature in KubeVirt allows mounting a host file or directory owned by the user with UID 107 into a VM. However, prior to version 1.6.1 and 1.7.0, the implementation of this feature and more specifically the `DiskOrCreate` option (which creates a file if it doesn't exist) has a logic bug that allows an attacker to read and write arbitrary files owned by more privileged users on the host system. Versions 1.6.1 and 1.7.0 fix the issue.

CVSS Metrics

  • v4.0HIGHScore: 8.5CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
  • v4.0HIGHScore: 8.5CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  • v3.1HIGHScore: 7.7CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

EPSS Trends

Current EPSS score: 0.21% Percentile: 11%

Techniques & Countermeasures

  • CWE-200Exposure of Sensitive Information to an Unauthorized Actor

    The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

  • CWE-732Incorrect Permission Assignment for Critical Resource

    The product specifies permissions for a security-critical resource in a way that allows that resource to be read or modified by unintended actors.

Affected Systems

  • kubevirt.iokubevirt

    < 1.6.1 | ≥ 1.7.0-alpha.0, < 1.7.0-rc.0 | ≥ 1.6.2, < 1.7.0-rc.0

  • kubevirtkubevirt

    1.7.0:alpha0 | 1.7.0:beta0 | < 1.6.1 | ≥ 1.7.0-alpha.0, < 1.7.0-rc.0

References (6)