Kata Containers - Containers have access to the guest root filesystem device
Vulnerability Description
Kata Containers doesn't restrict containers from accessing the guest's root filesystem device. Malicious containers can exploit this to gain code execution on the guest and masquerade as the kata-agent. This issue affects Kata Containers 1.11 versions earlier than 1.11.1; Kata Containers 1.10 versions earlier than 1.10.5; and Kata Containers 1.9 and earlier versions.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2020-2023
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- Yuval Avrahami, Palo Alto Networks
References
- https://github.com/kata-containers/runtime/pull/2487
- https://github.com/kata-containers/runtime/pull/2477
- https://github.com/kata-containers/runtime/issues/2488
- https://github.com/kata-containers/agent/issues/791
- https://github.com/kata-containers/agent/pull/792
- https://github.com/kata-containers/runtime/releases/tag/1.11.1
- https://github.com/kata-containers/runtime/releases/tag/1.10.5
More from Kata Containers
View All →Affected Vendor
Kata Containers
View all reports →