MEDIUM🇬🇧 English

CVE-2026-44210

CVSS 5.8v4.0pub. 2026-07-23upd. 2026-08-06

Kata Containers to projekt open source implementujący lekkie Virtual Machines działające jak kontenery. Wersje poniżej 3.31.0 posiadają domyślną konfigurację pozwalającą twórcom podów wstrzykiwać dowolne argumenty wiersza poleceń do procesu virtiofsd poprzez adnotację podu `io.katacontainers.config.hypervisor.virtio_fs_extra_args`. Wstrzyknięciem `-o source=/` wraz z `--no-announce-submounts` i `--sandbox=none` atakujący może zmienić udostępniany katalog virtiofsd tak, aby serwował cały root filesystem hosta do VM gościa. W połączeniu z adnotacją `kernel_params` (również domyślnie włączoną) do aktywacji konsoli debugowania agenta, atakujący może zamontować filesystem hosta wewnątrz VM i odczytać lub zapisać dowolny plik na hoście, w tym /etc/shadow. Wersja 3.31.0 załata tę podatność.

Pokaż oryginał (EN)

Kata Containers is an open source project focusing on a standard implementation of lightweight Virtual Machines (VMs) that perform like containers. Versions prior to 3.31.0 ship with a default configuration that allows pod creators to inject arbitrary command-line arguments into the virtiofsd process through the `io.katacontainers.config.hypervisor.virtio_fs_extra_args` pod annotation. By injecting `-o source=/` along with `--no-announce-submounts` and `--sandbox=none`, an attacker can override the virtiofsd shared directory to serve the entire host root filesystem into the guest VM. Combined with the `kernel_params` annotation (also enabled by default) to activate the agent debug console, the attacker can mount the host filesystem from inside the VM and read or write any file on the host, including /etc/shadow. Version 3.31.0 patches the issue.

CVSS Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:N/SC:H/SI:H/SA:H/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  • Katacontainers Kata Containers

    APP
    Katacontainers
    < 3.31.0
🔵
ZWERYFIKUJ U PRODUCENTA
Brak jednoznacznych danych o patchu. Sprawdź referencje od producenta.
Tagi
Container
CWE
Referencje

Powiązane podatności

CVE-2026-24834CRITICAL9.3PL ✓ten sam produkt

Kata Containers: modyfikacja systemu plików VM umożliwia RCE jako root

CVE-2026-41326HIGH8.2ten sam produkt

Kata Containers is an open source project focusing on a standard implementation of lightweight Virtual Machine...

CVE-2026-24054HIGH8.8ten sam produkt

Kata Containers is an open source project focusing on a standard implementation of lightweight Virtual Machine...

CVE-2020-27151HIGH8.8ten sam produkt

An issue was discovered in Kata Containers through 1.11.3 and 2.x through 2.0-rc1. The runtime will execute bi...

CVE-2020-28914HIGH7.1ten sam vendor

An improper file permissions vulnerability affects Kata Containers prior to 1.11.5. When using a Kubernetes ho...