https://seclists.org/oss-sec/2026/q3/540: CVE-2026-77176: Kata-containers: insufficient validation of catecontainer mount and storage rules in genpolicy
Published Aug 20, 2026
·Updated
Affected Software
1 affected component
Kata Containers Kata Containers
Frequently Asked Questions
1
Which deployments are exposed to this issue?
The issue affects Kata Containers configurations that use genpolicy for Confidential Containers guest protection. The described attacker is a malicious host operator.
2
What level of access does an attacker need?
An attacker needs control as a host operator and must be able to exploit insufficient validation of CreateContainer mount and storage rules. This can allow arbitrary container-rootfs paths to be mounted over sensitive host locations or arbitrary content to be provisioned.
3
Is a fix available?
Yes. The issue was fixed in the referenced Kata Containers commit fe8eeefcd0bec13c037ceb8f0889e48b75db17ab, and the fix is planned for the upcoming 4.1.0 release.