Skip to content
CVSS 9.6 · CRITICAL

CVE-2026-50540Escape de sandbox y RCE como root en Kata Containers

Kata Containers is an open source project focusing on a standard implementation of lightweight Virtual Machines (VMs) that perform like containers. Prior to version 4.0.0, kata-runtime is vulnerable to host code execution via an unvalidated configuration path annotation. The runtime accepts an arbitrary io.katacontainers.config_path pod annotation and loads the referenced host TOML file without restriction. As a result, a pod user who can place a file at a host-visible path can supply a configuration that selects an attacker-controlled hypervisor or virtio-fs daemon binary, executing code as root on the host. This issue is fixed in version 4.0.0.

Ver en NVD

Análisis

Kata Containers suffers from a sandbox escape vulnerability that allows a pod user to execute arbitrary code as root on the host system via a malicious configuration path. If your infrastructure relies on Kata for workload isolation, you should update to version 4.0.0 immediately.

Severidad

Puntaje: 9.6(CRITICAL)
Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N
AV: NETWORK
AC: LOW
PR: LOW
UI: NONE
S: CHANGED
C: HIGH
I: HIGH
A: NONE
Tipo de falla (CWE): CWE-20CWE-22

EPSS

Sin puntaje EPSS aún (CVE muy reciente).

Descripción técnica

Kata Containers is an open source project focusing on a standard implementation of lightweight Virtual Machines (VMs) that perform like containers. Prior to version 4.0.0, kata-runtime is vulnerable to host code execution via an unvalidated configuration path annotation. The runtime accepts an arbitrary io.katacontainers.config_path pod annotation and loads the referenced host TOML file without restriction. As a result, a pod user who can place a file at a host-visible path can supply a configuration that selects an attacker-controlled hypervisor or virtio-fs daemon binary, executing code as root on the host. This issue is fixed in version 4.0.0.

Publicada: 7/8/2026, 21:17:28
Última modificación: 7/8/2026, 21:17:28

Referencias

InicioEventosBlogRecursosCursosEquipo