PT-2026-20867 · Cloud Hypervisor+1 · Cloud Hypervisor+1
Kostya-Oai
·
Published
2026-02-19
·
Updated
2026-03-06
·
CVE-2026-24834
CVSS v3.1
9.3
Critical
| Vector | AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Kata Containers versions prior to 3.27.0
Description
Kata Containers is an open source project focusing on a standard implementation of lightweight Virtual Machines (VMs) that perform like containers. An issue in Kata with Cloud Hypervisor allows a user of the container to modify the file system used by the Guest micro VM, potentially achieving arbitrary code execution as root within the guest VM. The issue does not impact the security of the Host or other containers/VMs running on the same Host. Exploitation requires the
CAP MKNOD capability. This allows a malicious actor to elevate privileges within the guest virtual machine and gain full control of the guest environment.Recommendations
Upgrade to Kata Containers version 3.27.0 or later.
Exploit
Fix
LPE
Incorrect Permission
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Cloud Hypervisor
Kata Containers