Vulnerability Description
A malicious guest compromised before a container creation (e.g. a malicious guest image or a guest running multiple containers) can trick the kata runtime into mounting the untrusted container filesystem on any host path, potentially allowing for code execution on the host. This issue affects: Kata Containers 1.11 versions earlier than 1.11.1; Kata Containers 1.10 versions earlier than 1.10.5; Kata Containers 1.9 and earlier versions.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Katacontainers | Runtime | <= 1.9 |
| Fedoraproject | Fedora | 31 |
Related Weaknesses (CWE)
References
- https://github.com/kata-containers/runtime/issues/2712Third Party Advisory
- https://github.com/kata-containers/runtime/pull/2713Third Party Advisory
- https://github.com/kata-containers/runtime/releases/tag/1.10.5Release NotesThird Party Advisory
- https://github.com/kata-containers/runtime/releases/tag/1.11.1Release NotesThird Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedorapro
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedorapro
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedorapro
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedorapro
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedorapro
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedorapro
- https://github.com/kata-containers/runtime/issues/2712Third Party Advisory
- https://github.com/kata-containers/runtime/pull/2713Third Party Advisory
- https://github.com/kata-containers/runtime/releases/tag/1.10.5Release NotesThird Party Advisory
- https://github.com/kata-containers/runtime/releases/tag/1.11.1Release NotesThird Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedorapro
FAQ
What is CVE-2020-2026?
CVE-2020-2026 is a vulnerability with a CVSS score of 7.8 (HIGH). A malicious guest compromised before a container creation (e.g. a malicious guest image or a guest running multiple containers) can trick the kata runtime into mounting the untrusted container filesys...
How severe is CVE-2020-2026?
CVE-2020-2026 has been rated HIGH with a CVSS base score of 7.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2020-2026?
Check the references section above for vendor advisories and patch information. Affected products include: Katacontainers Runtime, Fedoraproject Fedora.