Link following in Kubevirt - CVE-2025-64437
Published: November 7, 2025 / Updated: November 7, 2025
Vulnerability details
The vulnerability allows a local user to compromise the target system.
The vulnerability exists due to an insecure link following issue when determining the root mount of a virt-launcher pod. A local administrator can create a specially crafted symbolic link to a critical file on the system and overwrite it with privileges of the application.
Affected software
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Server for SAP Applications 15
Containers Module
kubevirt-virtctl-debuginfo
kubevirt-virtctl
kubevirt-manifests
How to mitigate CVE-2025-64437
kubevirt-virtctl - update to 1.6.3-150700.3.13.1
kubevirt-manifests - update to 1.6.3-150700.3.13.1