Description
Kata Containers doesn't restrict containers from accessing the guest's root filesystem device. Malicious containers can exploit this to gain code execution on the guest and masquerade as the kata-agent. This issue affects Kata Containers 1.11 versions earlier than 1.11.1; Kata Containers 1.10 versions earlier than 1.10.5; and Kata Containers 1.9 and earlier versions.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-0858 | Kata Containers doesn't restrict containers from accessing the guest's root filesystem device. Malicious containers can exploit this to gain code execution on the guest and masquerade as the kata-agent. This issue affects Kata Containers 1.11 versions earlier than 1.11.1; Kata Containers 1.10 versions earlier than 1.10.5; and Kata Containers 1.9 and earlier versions. |
Github GHSA |
GHSA-6978-vg2j-cc9q | Improper Privilege Management and Execution with Unnecessary Privileges in Kata Containers |
References
History
No history.
Status: PUBLISHED
Assigner: palo_alto
Published:
Updated: 2024-09-17T01:15:36.499Z
Reserved: 2019-12-04T00:00:00.000Z
Link: CVE-2020-2023
No data.
Status : Modified
Published: 2020-06-10T18:15:11.280
Modified: 2024-11-21T05:24:28.640
Link: CVE-2020-2023
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA