Vulnerabilities (CVE)

Filtered by vendor Katacontainers Subscribe
Filtered by product Runtime
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2020-2026 1 Katacontainers 1 Runtime 2020-11-05 4.6 MEDIUM 8.8 HIGH
A malicious guest compromised before a container creation (e.g. a malicious guest image or a guest running multiple containers) can trick the kata runtime into mounting the untrusted container filesystem on any host path, potentially allowing for code execution on the host. This issue affects: Kata Containers 1.11 versions earlier than 1.11.1; Kata Containers 1.10 versions earlier than 1.10.5; Kata Containers 1.9 and earlier versions.
CVE-2020-2025 1 Katacontainers 1 Runtime 2020-05-21 4.6 MEDIUM 8.8 HIGH
Kata Containers before 1.11.0 on Cloud Hypervisor persists guest filesystem changes to the underlying image file on the host. A malicious guest can overwrite the image file to gain control of all subsequent guest VMs. Since Kata Containers uses the same VM image file with all VMMs, this issue may also affect QEMU and Firecracker based guests.