CVE-2026-77176: Kata-containers: insufficient validation of createcontainer mount and storage rules in genpolicy

Published Aug 17, 2026
·
Updated

A flaw was found in Kata Containers. In configurations utilizing genpolicy for Confidential Containers guest protection, a malicious host operator can exploit insufficient validation of CreateContainer mount and storage rules. This allows them to mount arbitrary container-rootfs paths over sensitive host locations or provision arbitrary content, potentially exposing confidential information or enabling the acceptance of attacker-controlled input.

Other sources

In Kata Containers configurations that use genpolicy for Confidential Containers guest protection, insufficient validation of CreateContainer mount and storage rules allows a malicious host operator to craft CreateContainer requests that cause arbitrary container-rootfs paths to be mounted over host-provided locations (such as /etc/hostname, /etc/hosts, /etc/resolv.conf, Kubernetes/Azure service-account token paths, and other volume mounts), or to provision arbitrary content under /dev/shm and /dev/termination-log. Applications that treat those paths as non-sensitive or guest-only may expose confidential information or accept attacker-controlled input. Standard Kata sandboxing is not affected.

Red Hat

Affected Software

1 affected component
Kata Containers Kata Containers

Event History

Aug 17, 2026
Data Sourced
via Red Hat·05:00 PM
DescriptionSeverityAffected Software
Aug 20, 2026
CVE Published
via MITRE·04:20 PM
Data Sourced
via MITRE·04:20 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Which deployments are exposed to this issue?

The issue affects Kata Containers configurations that use genpolicy for Confidential Containers guest protection. The provided information does not establish that deployments outside this configuration are affected.

2

What level of attacker access is required?

Exploitation requires a malicious host operator. The attacker can abuse insufficient validation of CreateContainer mount and storage rules.

3

What could an attacker achieve?

An attacker may mount arbitrary container-rootfs paths over sensitive host locations or provision arbitrary content. This can expose confidential information or cause acceptance of attacker-controlled input.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203