PT-2026-4806 · Kubevirt · Kubevirt
CVE-2025-14525
·
Published
2026-01-26
·
Updated
2026-07-08
CVSS v3.1
6.4
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:L/A:L |
Name of the Vulnerable Software and Affected Versions
kubevirt (affected versions not specified)
Description
A flaw exists in kubevirt where a user inside a virtual machine (VM), with an active guest agent, can trigger a denial of service. By reporting an excessive number of network interfaces, the agent can overwhelm the system’s capacity to store VM configuration updates, preventing modifications to the Virtual Machine Instance (VMI). This allows the VM user to hinder the VM administrator’s management capabilities, resulting in a denial of service for administrative operations.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
DoS
Allocation of Resources Without Limits
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Kubevirt