PatchSiren

kata-containers CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM kata-containers CVE published 2026-08-07

CVE-2026-64676

CVE-2026-64676 debrief: Kata Containers kata-agent authorization bypass in confidential-guest memory management allows host to tamper with in-guest memory, impacting availability and performance. The vulnerability exists in versions prior to 4.0.0 and is related to the mem-agent feature. This feature is off by default, but when enabled, it allows an untrusted host to invoke ttRPC methods without authoriza [truncated]

CRITICAL kata-containers CVE published 2026-08-07

CVE-2026-47243

A critical vulnerability was found in Kata Containers, a project for implementing lightweight Virtual Machines (VMs) that perform like containers. Prior to version 3.31.0, the runtime-rs standalone virtio-fs path is vulnerable to a guest-root to host-root escape. This issue allows an attacker with root-equivalent access inside the guest to bypass the guest virtio-fs client and submit raw FUSE requests dir [truncated]

MEDIUM kata-containers CVE published 2026-07-23

CVE-2026-44210

The CVE-2026-44210 vulnerability affects Kata Containers, an open-source project providing lightweight Virtual Machines (VMs). This vulnerability allows pod creators to inject arbitrary command-line arguments into the virtiofsd process, potentially enabling an attacker to read or write any file on the host. The vulnerability has a CVSS score of 5.8 and is classified as MEDIUM severity. Users of Kata Conta [truncated]