Improper Check or Handling of Exceptional Conditions in Kubevirt - CVE-2025-64435
Published: November 7, 2025 / Updated: November 7, 2025
Vulnerability identifier: #VU118182
CSH Severity: Medium
CVSS v4: 6 [CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-64435
CWE-ID: CWE-703
Exploitation vector: Remote access
Exploit availability:
Public exploit is available
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to improper conditions check in the virt-controller. A remote user can pass specially crafted input to the application and cause a denial of service condition on the target system.
Affected software
Kubevirt
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Server for SAP Applications 15
Containers Module
kubevirt-virtctl
kubevirt-virtctl-debuginfo
kubevirt-manifests
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Server for SAP Applications 15
Containers Module
kubevirt-virtctl
kubevirt-virtctl-debuginfo
kubevirt-manifests
How to mitigate CVE-2025-64435
Cybersecurity Help is currently unaware of any official solution to address this vulnerability.
kubevirt-virtctl - update to 1.7.0-150700.3.16.2
kubevirt-virtctl-debuginfo - update to 1.7.0-150700.3.16.2
kubevirt-manifests - update to 1.7.0-150700.3.16.2
kubevirt-virtctl-debuginfo - update to 1.7.0-150700.3.16.2
kubevirt-manifests - update to 1.7.0-150700.3.16.2