CVE-2020-2026
HIGHKata Containers runtime < 1.9.1 - Unauthenticated Arbitrary File Write via Filesystem Mount
Title source: llmDescription
A malicious guest compromised before a container creation (e.g. a malicious guest image or a guest running multiple containers) can trick the kata runtime into mounting the untrusted container filesystem on any host path, potentially allowing for code execution on the host. This issue affects: Kata Containers 1.11 versions earlier than 1.11.1; Kata Containers 1.10 versions earlier than 1.10.5; Kata Containers 1.9 and earlier versions.
References (10)
Core 10
Core References
Release Notes, Third Party Advisory x_refsource_misc
https://github.com/kata-containers/runtime/releases/tag/1.11.1
Release Notes, Third Party Advisory x_refsource_misc
https://github.com/kata-containers/runtime/releases/tag/1.10.5
Third Party Advisory x_refsource_misc
https://github.com/kata-containers/runtime/issues/2712
Third Party Advisory x_refsource_misc
https://github.com/kata-containers/runtime/pull/2713
Mailing List, Third Party Advisory vendor-advisory
x_refsource_fedora
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/NJAMOVB7DSOGX7J26QH5HZKU7GSSX2VU/
Mailing List, Third Party Advisory vendor-advisory
x_refsource_fedora
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/6JPBKAQBF3OR72N55GWM2TDYQP2OHK6H/
Mailing List, Third Party Advisory vendor-advisory
x_refsource_fedora
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/6W5MKF7HSAIL2AX2BX6RV4WWVGUIKVLS/
Mailing List, Third Party Advisory vendor-advisory
x_refsource_fedora
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/XWACJQSMY5BVDMVTF3FBN7HZSOSFOG3Q/
Mailing List, Third Party Advisory vendor-advisory
x_refsource_fedora
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/QNJHSSPCKUGJDVXXIXK2JUWCRJDQX7CE/
Mailing List, Third Party Advisory vendor-advisory
x_refsource_fedora
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/2P7FHA4AF6Y6PAVJBTTQPUEHXZQUOF3P/
Scores
CVSS v3
7.8
EPSS
0.0047
EPSS Percentile
37.3%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H
Details
CWE
CWE-59
Status
published
Products (3)
fedoraproject/fedora
31
kata-containers/runtime
0 - 1.9.1Go
katacontainers/runtime
< 1.9
Published
Jun 10, 2020
Tracked Since
Feb 18, 2026