CVE-2020-2024: Kata Containers - Guests can trick the kata-runtime into unmounting any mount point on the host
An improper link resolution vulnerability affects Kata Containers versions prior to 1.11.0. Upon container teardown, a malicious guest can trick the kata-runtime into unmounting any mount point on the host and all mount points underneath it, potentiality resulting in a host DoS.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Kata Containersto a version that resolves this vulnerability.Fixed in 1.11.0
Event History
Frequently Asked Questions
What is CVE-2020-2024?
CVE-2020-2024 is an improper link resolution vulnerability affecting Kata Containers versions prior to 1.11.0.
How does CVE-2020-2024 impact systems?
CVE-2020-2024 allows a malicious guest to trick the kata-runtime into unmounting any mount point on the host, potentially leading to a host DoS.
What is the severity of CVE-2020-2024?
CVE-2020-2024 has a severity keyword of medium with a CVSS score of 6.5.
How can I mitigate CVE-2020-2024?
To mitigate CVE-2020-2024, users should upgrade to Kata Containers version 1.11.0 or newer.