PT-2026-20867 · Cloud Hypervisor+1 · Cloud Hypervisor+1

Kostya-Oai

·

Published

2026-02-19

·

Updated

2026-03-06

·

CVE-2026-24834

CVSS v3.1

9.3

Critical

VectorAV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Kata Containers versions prior to 3.27.0
Description Kata Containers is an open source project focusing on a standard implementation of lightweight Virtual Machines (VMs) that perform like containers. An issue in Kata with Cloud Hypervisor allows a user of the container to modify the file system used by the Guest micro VM, potentially achieving arbitrary code execution as root within the guest VM. The issue does not impact the security of the Host or other containers/VMs running on the same Host. Exploitation requires the CAP MKNOD capability. This allows a malicious actor to elevate privileges within the guest virtual machine and gain full control of the guest environment.
Recommendations Upgrade to Kata Containers version 3.27.0 or later.

Exploit

Fix

LPE

Incorrect Permission

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

AZL-77976
CVE-2026-24834
GHSA-WWJ6-VGHV-5P64
GO-2026-4517
SUSE-SU-2026:0757-1

Affected Products

Cloud Hypervisor
Kata Containers