CVE-2026-77176 is a vulnerability in Kata Containers that affects configurations using genpolicy for guest root filesystem protection. The vulnerability has a CVSS score of 8.1 (High). It results from insufficient validation of CreateContainer mount and storage rules. An attacker with low-level host access can manipulate container creation requests to mount arbitrary guest rootfs paths over sensitive host locations. This can expose sensitive host files, configuration data, service-account tokens, and other mounted resources. The flaw may also allow attacker-controlled content to be placed in locations such as /dev/shm and /dev/termination-log. Affected versions include Kata Containers configurations using genpolicy, including versions prior to the 4.1.0. Exploitation could therefore compromise the isolation boundary between containers and the host system.
We recommend you to update Kata Containers to the version 4.1.0.[/subscribe_to_unlock_form]
CVE-2026-77176 is a vulnerability in Kata Containers that affects configurations using genpolicy for guest root filesystem protection. The vulnerability has a CVSS score of 8.1 (High). It results from insufficient validation of CreateContainer mount and storage rules. An attacker with low-level host access can manipulate container creation requests to mount arbitrary guest rootfs paths over sensitive host locations. This can expose sensitive host files, configuration data, service-account tokens, and other mounted resources. The flaw may also allow attacker-controlled content to be placed in locations such as /dev/shm and /dev/termination-log. Affected versions include Kata Containers configurations using genpolicy, including versions prior to the 4.1.0. Exploitation could therefore compromise the isolation boundary between containers and the host system.
We recommend you to update Kata Containers to the version 4.1.0.[emaillocker id="1283"]
The following reports contain further technical details:
[/emaillocker]