Skip to content
Threat Feed

Product

Kata Containers

4 briefs RSS
high advisory

Arbitrary Mount Vulnerability in Kata Containers Confidential Containers

A vulnerability in Kata Containers, specifically when using genpolicy for Confidential Containers guest protection, allows a malicious host operator to bypass mount and storage rule validations during CreateContainer operations.

Red Hat OpenShift Container Platform 4 +1 privilege-escalation container-security cloud-security
1t 1c
high advisory

Unauthorized mem-agent ttRPC methods in Kata Containers

A vulnerability in the Kata Containers mem-agent component allows an untrusted host to invoke unauthorized ttRPC methods, resulting in potential memory tampering within confidential guest environments.

Kata Containers
1t 1c
high advisory

Kata Containers Guest-to-Host Root Escape via Virtiofs FUSE_SYMLINK

A vulnerability in Kata Containers allows a guest root user to escalate privileges to host root by exploiting the virtiofs shared file system to create arbitrary symlinks on the host.

kata-containers/kata-containers +1 kata-containers virtiofs fuse privilege-escalation container-escape
2r 1t 1c updated
high advisory

Kata Containers CopyFile Policy Subversion via Symlinks

An oversight in the CopyFile policy in Kata Containers allows untrusted hosts to write to arbitrary locations inside the guest workload image via symlinks, enabling binary overwrites and data exfiltration.

kata-containers/kata-containers kata-containers container-escape symlink
3r 2t 1c