Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-41326

Опубликовано: 22 апр. 2026
Источник: redhat
CVSS3: 8.8
EPSS Низкий

Описание

Kata Containers is an open source project focusing on a standard implementation of lightweight Virtual Machines (VMs) that perform like containers. From v3.4.0 to v3.28.0, an oversight in the CopyFile policy (and perhaps the CopyFile handler) allows untrusted hosts to write to arbitrary locations inside the guest workload image. This can be used to overwrite binaries inside the guest and exfiltrate data from containers; even those running inside CVMs. This vulnerability is fixed in v3.29.0.

A flaw was found in Kata Containers. An oversight in the CopyFile policy (and perhaps the CopyFile handler) allows untrusted hosts to write to arbitrary locations inside the guest workload image. This can be used to overwrite binaries inside the guest and exfiltrate data from containers; even those running inside CVMs.

Отчет

This flaw in the CopyFile policy of Kata Containers allows untrusted hosts to write to arbitrary locations within a guest workload image. This could lead to the overwriting of binaries inside the guest and the exfiltration of data from containers, including those running within Confidential Virtual Machines (CVMs).

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Confidential Compute Attestationopenshift-sandboxed-containers/osc-cloud-api-adaptor-rhel9Not affected
Confidential Compute Attestationopenshift-sandboxed-containers/osc-monitor-rhel9Not affected
Confidential Compute Attestationopenshift-sandboxed-containers/osc-operator-bundleNot affected
Confidential Compute Attestationopenshift-sandboxed-containers/osc-podvm-builder-rhel9Not affected
Confidential Compute Attestationopenshift-sandboxed-containers/osc-podvm-payload-rhel9Affected
Confidential Compute Attestationopenshift-sandboxed-containers/osc-rhel9-operatorNot affected
Red Hat OpenShift Container Platform 4cri-oNot affected
Red Hat OpenShift Container Platform 4openshift4/ose-azure-file-csi-driver-rhel9Not affected
Red Hat OpenShift Container Platform 4rhcosAffected
Red Hat OpenShift Container Platform 4.19rhcos-4.19.9.6.202606100451FixedRHSA-2026:2520017.06.2026

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-1220
https://bugzilla.redhat.com/show_bug.cgi?id=2460859kata-containers: Arbitrary file write inside guest image via CopyFile policy

EPSS

Процентиль: 19%
0.00269
Низкий

8.8 High

CVSS3

Связанные уязвимости

CVSS3: 8.2
nvd
4 месяца назад

Kata Containers is an open source project focusing on a standard implementation of lightweight Virtual Machines (VMs) that perform like containers. From v3.4.0 to v3.28.0, an oversight in the CopyFile policy (and perhaps the CopyFile handler) allows untrusted hosts to write to arbitrary locations inside the guest workload image. This can be used to overwrite binaries inside the guest and exfiltrate data from containers; even those running inside CVMs. This vulnerability is fixed in v3.29.0.

CVSS3: 8.2
github
3 месяца назад

Kata Container has CopyFile Policy Subversion via Symlinks

EPSS

Процентиль: 19%
0.00269
Низкий

8.8 High

CVSS3