PT-2025-39220 · Unknown · Kata Containers

CVE-2025-58354

·

Published

2025-09-23

·

Updated

2025-09-24

CVSS v4.0

6.9

Medium

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Kata Containers versions prior to 3.21.0
Description Kata Containers is an open source project focused on lightweight Virtual Machines that function like containers. In versions prior to 3.21.0, a malicious host can bypass initdata verification. Specifically, on TDX systems running confidential guests, a malicious host can selectively fail Input/Output (IO) operations to skip initdata verification. This allows an attacker to launch arbitrary workloads while successfully attesting to Trustee, impersonating a benign workload.
Recommendations Update to Kata Containers version 3.21.0 or later.

Exploit

Fix

Improper Check for Exceptional Conditions

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-58354
GHSA-989W-4XR2-WW9M

Affected Products

Kata Containers