CVE-2020-2026
Kata Containers - Guests can trick the kata-runtime into mounting the container image on any host path
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
A malicious guest compromised before a container creation (e.g. a malicious guest image or a guest running multiple containers) can trick the kata runtime into mounting the untrusted container filesystem on any host path, potentially allowing for code execution on the host. This issue affects: Kata Containers 1.11 versions earlier than 1.11.1; Kata Containers 1.10 versions earlier than 1.10.5; Kata Containers 1.9 and earlier versions.
Un invitado malicioso comprometido antes de la creación de un contenedor (por ejemplo, una imagen maliciosa del invitado o un invitado que ejecuta múltiples contenedores) puede engañar al tiempo de ejecución de kata para que monte el sistema de archivos del contenedor no confiable en cualquier ruta de host, permitiendo potencialmente una ejecución de código en el host. Este problema afecta a: Kata Containers versiones 1.11 anteriores a 1.11.1; Kata Containers versiones 1.10 anteriores a 1.10.5; Kata Containers versiones 1.9 y anteriores
CVSS Scores
SSVC
- Decision:-
Timeline
- 2019-12-04 CVE Reserved
- 2020-06-10 CVE Published
- 2023-03-08 EPSS Updated
- 2024-09-16 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-59: Improper Link Resolution Before File Access ('Link Following')
CAPEC
References (10)
URL | Tag | Source |
---|---|---|
https://github.com/kata-containers/runtime/issues/2712 | Third Party Advisory | |
https://github.com/kata-containers/runtime/pull/2713 | Third Party Advisory | |
https://github.com/kata-containers/runtime/releases/tag/1.10.5 | Release Notes | |
https://github.com/kata-containers/runtime/releases/tag/1.11.1 | Release Notes |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Katacontainers Search vendor "Katacontainers" | Runtime Search vendor "Katacontainers" for product "Runtime" | <= 1.9 Search vendor "Katacontainers" for product "Runtime" and version " <= 1.9" | - |
Affected
| ||||||
Katacontainers Search vendor "Katacontainers" | Runtime Search vendor "Katacontainers" for product "Runtime" | >= 1.10 < 1.10.5 Search vendor "Katacontainers" for product "Runtime" and version " >= 1.10 < 1.10.5" | - |
Affected
| ||||||
Katacontainers Search vendor "Katacontainers" | Runtime Search vendor "Katacontainers" for product "Runtime" | >= 1.11 < 1.11.1 Search vendor "Katacontainers" for product "Runtime" and version " >= 1.11 < 1.11.1" | - |
Affected
| ||||||
Fedoraproject Search vendor "Fedoraproject" | Fedora Search vendor "Fedoraproject" for product "Fedora" | 31 Search vendor "Fedoraproject" for product "Fedora" and version "31" | - |
Affected
|