Vulnerability Description
Kata Containers before 1.11.0 on Cloud Hypervisor persists guest filesystem changes to the underlying image file on the host. A malicious guest can overwrite the image file to gain control of all subsequent guest VMs. Since Kata Containers uses the same VM image file with all VMMs, this issue may also affect QEMU and Firecracker based guests.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Katacontainers | Runtime | < 1.11.0 |
Related Weaknesses (CWE)
References
- https://github.com/kata-containers/runtime/pull/2487PatchThird Party Advisory
- https://github.com/kata-containers/runtime/pull/2487PatchThird Party Advisory
FAQ
What is CVE-2020-2025?
CVE-2020-2025 is a vulnerability with a CVSS score of 8.8 (HIGH). Kata Containers before 1.11.0 on Cloud Hypervisor persists guest filesystem changes to the underlying image file on the host. A malicious guest can overwrite the image file to gain control of all subs...
How severe is CVE-2020-2025?
CVE-2020-2025 has been rated HIGH with a CVSS base score of 8.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2020-2025?
Check the references section above for vendor advisories and patch information. Affected products include: Katacontainers Runtime.