CyberRota Analysis
AI-GeneratedA vulnerability in Kata Containers allows a malicious host operator to exploit inadequate validation of mount and storage rules in configurations using genpolicy for Confidential Containers guest protection. This can lead to arbitrary container-root filesystem paths being mounted over sensitive host locations, risking exposure of confidential information and enabling the injection of attacker-controlled content. Organizations utilizing Kata Containers for sensitive workloads should prioritize addressing this issue to safeguard their data integrity and confidentiality.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
A flaw was found in Kata Containers. In configurations utilizing genpolicy for Confidential Containers guest protection, a malicious host operator can exploit insufficient validation of CreateContainer mount and storage rules. This allows them to mount arbitrary container-rootfs paths over sensitive host locations or provision arbitrary content, potentially exposing confidential information or enabling the acceptance of attacker-controlled input.