CVE-2020-2023

LOW

Kata Containers <1.11.1, <1.10.5, <=1.9 - Remote Code Execution

Title source: manual
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2020-2023. PoCs published by ssst0n3.

AI-analyzed exploit summary This repository contains a proof-of-concept exploit for CVE-2020-2023, targeting Kata Containers. The exploit demonstrates container escape techniques by manipulating the guest filesystem via mknod and debugfs, leading to privilege escalation and remote code execution on the host.

Description

Kata Containers doesn't restrict containers from accessing the guest's root filesystem device. Malicious containers can exploit this to gain code execution on the guest and masquerade as the kata-agent. This issue affects Kata Containers 1.11 versions earlier than 1.11.1; Kata Containers 1.10 versions earlier than 1.10.5; and Kata Containers 1.9 and earlier versions.

Exploits (1)

nomisec WORKING POC 3 stars
by ssst0n3 · poc
https://github.com/ssst0n3/kata-cve-2020-2023-poc

This repository contains a proof-of-concept exploit for CVE-2020-2023, targeting Kata Containers. The exploit demonstrates container escape techniques by manipulating the guest filesystem via mknod and debugfs, leading to privilege escalation and remote code execution on the host.

Classification
Working Poc 95%
Attack Type
Lpe
Complexity
Moderate
Reliability
Reliable
Target: Kata Containers 1.11.0
Auth required
Prerequisites: Access to a Kata Containers environment with KVM support · Root access within the container
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (7)

Core 7
Core References
Patch, Third Party Advisory x_refsource_misc
https://github.com/kata-containers/runtime/pull/2487
Patch, Third Party Advisory x_refsource_misc
https://github.com/kata-containers/runtime/pull/2477
Patch, Third Party Advisory x_refsource_misc
https://github.com/kata-containers/runtime/issues/2488
Third Party Advisory x_refsource_misc
https://github.com/kata-containers/agent/issues/791
Release Notes, Third Party Advisory x_refsource_misc
https://github.com/kata-containers/runtime/releases/tag/1.11.1
Release Notes, Third Party Advisory x_refsource_misc
https://github.com/kata-containers/runtime/releases/tag/1.10.5

Scores

CVSS v3 3.8
EPSS 0.0176
EPSS Percentile 83.1%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:L/A:N

Details

CWE
CWE-250
Status published
Products (3)
kata-containers/agent 0 - 1.9.1Go
kata-containers/runtime 0 - 1.9.1Go
katacontainers/runtime < 1.9
Published Jun 10, 2020
Tracked Since Feb 18, 2026