CVE-2025-58354: Kata Containers coco-tdx malicious host can circumvent initdata verification
Kata Containers coco-tdx malicious host can circumvent initdata verification
Other sources
Kata Containers is an open source project focusing on a standard implementation of lightweight Virtual Machines (VMs) that perform like containers. In Kata Containers versions from 3.20.0 and before, a malicious host can circumvent initdata verification. On TDX systems running confidential guests, a malicious host can selectively fail IO operations to skip initdata verification. This allows an attacker to launch arbitrary workloads while being able to attest successfully to Trustee impersonating any benign workload. This issue has been patched in Kata Containers version 3.21.0.
— NVD
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-58354?
CVE-2025-58354 has a high severity rating due to its potential to allow malicious hosts to bypass initdata verification on affected systems.
How do I fix CVE-2025-58354?
To mitigate CVE-2025-58354, upgrade Kata Containers to version 3.21.0 or higher, which includes the necessary patches.
Which versions of Kata Containers are affected by CVE-2025-58354?
CVE-2025-58354 affects all versions of Kata Containers from 3.20.0 and earlier.
What types of systems are vulnerable to CVE-2025-58354?
CVE-2025-58354 impacts systems using Kata Containers on TDX architecture and similar hardware configurations.
Can CVE-2025-58354 lead to remote code execution?
Yes, if exploited, CVE-2025-58354 could potentially allow remote code execution through the vulnerability in initdata verification.