CVE-2025-64436: KubeVirt Excessive Role Permissions Could Enable Unauthorized VMI Migrations Between Nodes
(updated )
_Short summary of the problem. Make the impact and severity as clear as possible.
The permissions granted to the virt-handler service account, such as the ability to update VMI and patch nodes, could be abused to force a VMI migration to an attacker-controlled node.
References
Code Behaviors & Features
Detect and mitigate CVE-2025-64436 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →