Incorrect permission assignment for critical resource in Kubevirt - CVE-2025-64324
Published: November 7, 2025 / Updated: November 7, 2025
Vulnerability identifier: #VU118175
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-64324
CWE-ID: CWE-732
Exploitation vector: Remote access
Exploit availability:
Public exploit is available
Vulnerability details
The vulnerability allows a remote attacker to compromise the target system.
The vulnerability exists due to a logic bug in the code of the virt-handler component. A remote attacker can read and write arbitrary files on the system.
Affected software
Kubevirt
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Server for SAP Applications 15
Containers Module
kubevirt-virtctl-debuginfo
kubevirt-virtctl
kubevirt-manifests
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Server for SAP Applications 15
Containers Module
kubevirt-virtctl-debuginfo
kubevirt-virtctl
kubevirt-manifests
How to mitigate CVE-2025-64324
Cybersecurity Help is currently unaware of any official solution to address this vulnerability.
kubevirt-virtctl-debuginfo - update to 1.6.3-150700.3.13.1
kubevirt-virtctl - update to 1.6.3-150700.3.13.1
kubevirt-manifests - update to 1.6.3-150700.3.13.1
kubevirt-virtctl - update to 1.6.3-150700.3.13.1
kubevirt-manifests - update to 1.6.3-150700.3.13.1