Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-50540

Опубликовано: 20 июл. 2026
Источник: redhat
CVSS3: 8.8

Описание

A flaw was found in Kata Containers, affecting both its Rust and Go runtimes. An authenticated pod user can exploit this by setting the io.katacontainers.config_path annotation to an arbitrary configuration file on the host. This allows the attacker to control privileged runtime settings, leading to the execution of malicious binaries as root on the host system. The primary consequence is arbitrary code execution with elevated privileges.

Отчет

This is an Important flaw in Kata Containers that allows an authenticated pod user to achieve arbitrary code execution as root on the host. By manipulating the io.katacontainers.config_path annotation, an attacker can point to a malicious configuration file, leading to a critical bypass of container isolation and privilege escalation within OpenShift Container Platform deployments.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Confidential Compute Attestationopenshift-sandboxed-containers/osc-monitor-rhel9Affected
Red Hat OpenShift Container Platform 4kata-containersAffected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-20
https://bugzilla.redhat.com/show_bug.cgi?id=2500228kata-runtime: kata-runtime-rs: Kata Containers: Arbitrary code execution via manipulated configuration path

8.8 High

CVSS3

8.8 High

CVSS3

Уязвимость CVE-2026-50540