REDHAT-BUG-2441025: High severity Kata Containers Kata Containers vulnerability
Kata Containers is an open source project focusing on a standard implementation of lightweight Virtual Machines (VMs) that perform like containers. In versions prior to 3.27.0, an issue in Kata with Cloud Hypervisor allows a user of the container to modify the file system used by the Guest micro VM ultimately achieving arbitrary code execution as root in said VM. The current understanding is this doesn’t impact the security of the Host or of other containers / VMs running on that Host (note that arm64 QEMU lacks NVDIMM read-only support: It is believed that until the upstream QEMU gains this capability, a guest write could reach the image file). Version 3.27.0 patches the issue.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
kata-containersto a version that resolves this vulnerability.Fixed in 3.27.0
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-2441025?
The severity of REDHAT-BUG-2441025 is high, rated at 7.
How do I fix REDHAT-BUG-2441025?
To fix REDHAT-BUG-2441025, upgrade Kata Containers to version 3.27.0 or later.
What is the impact of REDHAT-BUG-2441025?
The impact of REDHAT-BUG-2441025 allows users of the container to modify the file system used by the Guest micro VM.
Which versions are affected by REDHAT-BUG-2441025?
Versions of Kata Containers prior to 3.27.0 are affected by REDHAT-BUG-2441025.
What is Kata Containers?
Kata Containers is an open source project that focuses on combining lightweight Virtual Machines with the performance of containers.