PT-2025-39220 · Unknown · Kata Containers

Published

2025-09-23

·

Updated

2025-09-24

·

CVE-2025-58354

CVSS v4.0

6.9

Medium

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Kata Containers versions prior to 3.21.0
Description Kata Containers is an open source project focused on lightweight Virtual Machines that function like containers. In versions prior to 3.21.0, a malicious host can bypass initdata verification. Specifically, on TDX systems running confidential guests, a malicious host can selectively fail Input/Output (IO) operations to skip initdata verification. This allows an attacker to launch arbitrary workloads while successfully attesting to Trustee, impersonating a benign workload.
Recommendations Update to Kata Containers version 3.21.0 or later.

Exploit

Fix

Improper Check for Exceptional Conditions

Weakness Enumeration

Related Identifiers

CVE-2025-58354
GHSA-989W-4XR2-WW9M

Affected Products

Kata Containers