Import Source
https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-70414.json
JSON Data
https://api.test.osv.dev/v1/vulns/AZL-70414
Upstream
Published
2025-11-18T23:15:55Z
Modified
2026-04-01T05:21:55.515286Z
Summary
CVE-2025-64324 affecting package kubevirt for versions less than 1.6.3-1
Details

KubeVirt is a virtual machine management add-on for Kubernetes. The hostDisk feature in KubeVirt allows mounting a host file or directory owned by the user with UID 107 into a VM. However, prior to version 1.6.1 and 1.7.0, the implementation of this feature and more specifically the DiskOrCreate option (which creates a file if it doesn't exist) has a logic bug that allows an attacker to read and write arbitrary files owned by more privileged users on the host system. Versions 1.6.1 and 1.7.0 fix the issue.

References

Affected packages

Azure Linux:3 / kubevirt

Package

Name
kubevirt
Purl
pkg:rpm/azure-linux/kubevirt

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.6.3-1

Database specific

source
"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-70414.json"