Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-41326

Опубликовано: 24 апр. 2026
Источник: nvd
CVSS3: 8.2
CVSS3: 8.8
EPSS Низкий

Описание

Kata Containers is an open source project focusing on a standard implementation of lightweight Virtual Machines (VMs) that perform like containers. From v3.4.0 to v3.28.0, an oversight in the CopyFile policy (and perhaps the CopyFile handler) allows untrusted hosts to write to arbitrary locations inside the guest workload image. This can be used to overwrite binaries inside the guest and exfiltrate data from containers; even those running inside CVMs. This vulnerability is fixed in v3.29.0.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:katacontainers:confidential_containers:*:*:*:*:*:*:*:*
Версия от 0.9.0 (включая) до 0.20.0 (исключая)
cpe:2.3:a:katacontainers:kata_containers:*:*:*:*:*:*:*:*
Версия от 3.4.0 (включая) до 3.29.0 (исключая)

EPSS

Процентиль: 19%
0.00269
Низкий

8.2 High

CVSS3

8.8 High

CVSS3

Дефекты

CWE-61
CWE-1220

Связанные уязвимости

CVSS3: 8.8
redhat
4 месяца назад

Kata Containers is an open source project focusing on a standard implementation of lightweight Virtual Machines (VMs) that perform like containers. From v3.4.0 to v3.28.0, an oversight in the CopyFile policy (and perhaps the CopyFile handler) allows untrusted hosts to write to arbitrary locations inside the guest workload image. This can be used to overwrite binaries inside the guest and exfiltrate data from containers; even those running inside CVMs. This vulnerability is fixed in v3.29.0.

CVSS3: 8.2
github
3 месяца назад

Kata Container has CopyFile Policy Subversion via Symlinks

EPSS

Процентиль: 19%
0.00269
Низкий

8.2 High

CVSS3

8.8 High

CVSS3

Дефекты

CWE-61
CWE-1220