CVE-2025-14525

Severity
6.4MEDIUM
EPSS
0.0%
top 95.06%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJan 26
Latest updateFeb 2

Description

A flaw was found in kubevirt. A user within a virtual machine (VM), if the guest agent is active, can exploit this by causing the agent to report an excessive number of network interfaces. This action can overwhelm the system's ability to store VM configuration updates, effectively blocking changes to the Virtual Machine Instance (VMI). This allows the VM user to restrict the VM administrator's ability to manage the VM, leading to a denial of service for administrative operations.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:L/A:LExploitability: 3.1 | Impact: 2.7

Affected Packages1 packages

🔴Vulnerability Details

4
OSV
KubeVirt Guest Agent DoS via Excessive Network Interface Reports in kubevirt.io/kubevirt2026-02-02
OSV
KubeVirt Guest Agent DoS via Excessive Network Interface Reports2026-01-26
CVEList
Kubevirt: kubevirt: vm administration denial of service via guest agent2026-01-26
GHSA
KubeVirt Guest Agent DoS via Excessive Network Interface Reports2026-01-26

📋Vendor Advisories

1
Red Hat
kubevirt: kubevirt: VM administration denial of service via guest agent2026-01-09

🕵️Threat Intelligence

1
Wiz
CVE-2025-14525 Impact, Exploitability, and Mitigation Steps | Wiz
CVE-2025-14525 (MEDIUM CVSS 6.4) | A flaw was found in kubevirt | cvebase.io