A flaw was found in Kata Containers. In configurations utilizing genpolicy for Confidential Containers guest protection, a malicious host operator can exploit insufficient validation of CreateContainer mount and storage rules. This allows them to mount arbitrary container-rootfs paths over sensitive host locations or provision arbitrary content, potentially exposing confidential information or enabling the acceptance of attacker-controlled input.
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-08-20 17:19
Updated : 2026-09-01 12:17
NVD link : CVE-2026-77176
Mitre link : CVE-2026-77176
CVE.ORG link : CVE-2026-77176
JSON object : View
Products Affected
No product.
CWE
CWE-73
External Control of File Name or Path
