
Cloud Vulnerability DB
A community-led vulnerabilities database
A security vulnerability identified as CVE-2020-2026 was discovered in Kata Containers, affecting versions 1.11 earlier than 1.11.1, 1.10 earlier than 1.10.5, and 1.9 and earlier versions. The vulnerability allows a malicious guest that is compromised before container creation (such as through a malicious guest image or a guest running multiple containers) to trick the kata runtime into mounting an untrusted container filesystem on any host path, potentially enabling code execution on the host (CVE Mitre, NVD).
The vulnerability stems from the way Kata Containers handles filesystem mounting between the host and guest environments. The issue specifically involves the shared filesystem path mechanism where a malicious guest could manipulate the mounting process to gain unauthorized access to host paths. This security flaw was addressed by implementing a new directory structure for sandboxes and adding readonly restrictions to prevent unauthorized modifications (Runtime PR).
The vulnerability could allow an attacker to execute code on the host system by mounting an untrusted container filesystem on arbitrary host paths. This presents a significant security risk as it could lead to host system compromise and potential unauthorized access to host resources (CVE Mitre).
The vulnerability requires the attacker to have control of a guest container before its creation, either through a compromised guest image or by running multiple containers. The attack vector involves manipulating the container filesystem mounting process to gain unauthorized access to host paths (NVD).
The vulnerability was patched in Kata Containers versions 1.11.1 and 1.10.5. The fix involves creating two separate directories for each sandbox: one for host/guest shared mounts and another for the host/guest shared directory, with the mounts directory being bound read-only to prevent unauthorized modifications. Users are strongly encouraged to upgrade to these patched versions (Release 1.11.1, Release 1.10.5).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."